THREAT OPS › Threat News › [GHSA] GHSA-wjwr-xfp9-r66p (medium) — Open WebUI: Admin demoted through SSO role sync keeps read and write access to all users' notes
[GHSA] GHSA-wjwr-xfp9-r66p (medium) — Open WebUI: Admin demoted through SSO role sync keeps read and write access to all users' notes
GHSA-wjwr-xfp9-r66p Severity: medium CVE: CVE-2026-87014
Open WebUI: Admin demoted through SSO role sync keeps read and write access to all users' notes
## Summary
A user who is demoted from admin by an identity provider keeps admin-level read and write access to every user's notes, over any Socket.IO connection that was already open when the demotion happened. Open WebUI caches the user's role
Indicators of compromise
- ce3c175e260709f359d7e6cbb3132f0572098b95sha1
- CVE-2026-87014cve
Original source: https://github.com/advisories/GHSA-wjwr-xfp9-r66p