THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-wvm9-9g5j-623f (medium) — Open WebUI: Users denied by the OAuth role policy can still sign in via token exchange

[GHSA] GHSA-wvm9-9g5j-623f (medium) — Open WebUI: Users denied by the OAuth role policy can still sign in via token exchange

medgithub_advisoriesPublished 2026-09-10

GHSA-wvm9-9g5j-623f Severity: medium CVE: CVE-2026-88006

Open WebUI: Users denied by the OAuth role policy can still sign in via token exchange

## Summary Open WebUI's OAuth token exchange endpoint issues a session for a provider access token without running the OAuth role management that the normal OAuth login callback runs. A user whose provider roles the login callback would refuse, or would

Indicators of compromise

Original source: https://github.com/advisories/GHSA-wvm9-9g5j-623f