THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-wpmr-8h3q-fwj7 (high) — Open WebUI: Sign-in as another user via wildcard characters in the OAuth subject claim on SQLite

[GHSA] GHSA-wpmr-8h3q-fwj7 (high) — Open WebUI: Sign-in as another user via wildcard characters in the OAuth subject claim on SQLite

medgithub_advisoriesPublished 2026-09-10

GHSA-wpmr-8h3q-fwj7 Severity: high CVE: CVE-2026-87016

Open WebUI: Sign-in as another user via wildcard characters in the OAuth subject claim on SQLite

## Summary

On SQLite deployments, the lookup that maps an external identity to a local account does a substring match instead of an exact match. A subject value containing SQL wildcard characters therefore matches accounts the value was never is

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-wpmr-8h3q-fwj7