top of page
perceptive_background_267k.jpg

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.11.0, when ENABLE_OAUTH_TOKEN_EXCHANGE=True, /oauth/{pr…

Published:

4 August 2026 at 00:00:00

Alert date:

4 August 2026 at 23:03:55

Source:

nvd.nist.gov

Click to open the original link from this advisory

Identity & Access, Web Technologies, Emerging Technologies

A critical authentication bypass vulnerability exists in Open WebUI versions 0.8.0 through 0.11.0. When the ENABLE_OAUTH_TOKEN_EXCHANGE feature is enabled, the /oauth/{provider}/token/exchange endpoint accepts raw provider access tokens without verifying which OAuth client the token was originally issued to. This allows any attacker holding a valid access token from any client registered with the same OAuth provider to exchange it for a legitimate Open WebUI session. The flaw enables unauthorized access to user accounts, including tokens from applications the operator never authorized. The vulnerability stems from improper audience/client validation during the token exchange process. It has been patched in Open WebUI version 0.11.0 via two separate commits. Users are strongly advised to upgrade immediately or disable the OAuth token exchange feature as a mitigation.

Technical details

Mitigation steps:

Affected products:

Open WebUI 0.8.0
Open WebUI 0.9.0
Open WebUI 0.10.0

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page