THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-wjwr-xfp9-r66p (medium) — Open WebUI: Admin demoted through SSO role sync keeps read and write access to all users' notes

[GHSA] GHSA-wjwr-xfp9-r66p (medium) — Open WebUI: Admin demoted through SSO role sync keeps read and write access to all users' notes

highgithub_advisoriesPublished 2026-09-10

GHSA-wjwr-xfp9-r66p Severity: medium CVE: CVE-2026-87014

Open WebUI: Admin demoted through SSO role sync keeps read and write access to all users' notes

## Summary

A user who is demoted from admin by an identity provider keeps admin-level read and write access to every user's notes, over any Socket.IO connection that was already open when the demotion happened. Open WebUI caches the user's role

Indicators of compromise

Original source: https://github.com/advisories/GHSA-wjwr-xfp9-r66p