THREAT OPS › Threat News › [GHSA] GHSA-wvm9-9g5j-623f (medium) — Open WebUI: Users denied by the OAuth role policy can still sign in via token exchange
[GHSA] GHSA-wvm9-9g5j-623f (medium) — Open WebUI: Users denied by the OAuth role policy can still sign in via token exchange
GHSA-wvm9-9g5j-623f Severity: medium CVE: CVE-2026-88006
Open WebUI: Users denied by the OAuth role policy can still sign in via token exchange
## Summary Open WebUI's OAuth token exchange endpoint issues a session for a provider access token without running the OAuth role management that the normal OAuth login callback runs. A user whose provider roles the login callback would refuse, or would
Indicators of compromise
- CVE-2026-88006cve
Original source: https://github.com/advisories/GHSA-wvm9-9g5j-623f