THREAT OPS › Threat News › [NVD] CVE-2026-70482 (HIGH 8.1) — Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.11.0, when ENABLE_OAUTH_TOKEN_EXCHANGE=True, /oauth/{provider}/token/exchange accepts a raw provider access token and validates it by calling the provider userinfo endpoint wi
[NVD] CVE-2026-70482 (HIGH 8.1) — Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.11.0, when ENABLE_OAUTH_TOKEN_EXCHANGE=True, /oauth/{provider}/token/exchange accepts a raw provider access token and validates it by calling the provider userinfo endpoint wi
CVE-2026-70482 CVSS: 8.1 HIGH Published: 2026-08-04T20:16:55.190
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.11.0, when ENABLE_OAUTH_TOKEN_EXCHANGE=True, /oauth/{provider}/token/exchange accepts a raw provider access token and validates it by calling the provider userinfo endpoint without confirming which OAuth client the token was issu
Indicators of compromise
- CVE-2026-70482cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-70482