


Perceptive Security
SOC/SIEM Consultancy

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.11.0, when ENABLE_OAUTH_TOKEN_EXCHANGE=True, /oauth/{pr…
Published:
4 August 2026 at 00:00:00
Alert date:
4 August 2026 at 23:03:55
Source:
nvd.nist.gov
Identity & Access, Web Technologies, Emerging Technologies
A critical authentication bypass vulnerability exists in Open WebUI versions 0.8.0 through 0.11.0. When the ENABLE_OAUTH_TOKEN_EXCHANGE feature is enabled, the /oauth/{provider}/token/exchange endpoint accepts raw provider access tokens without verifying which OAuth client the token was originally issued to. This allows any attacker holding a valid access token from any client registered with the same OAuth provider to exchange it for a legitimate Open WebUI session. The flaw enables unauthorized access to user accounts, including tokens from applications the operator never authorized. The vulnerability stems from improper audience/client validation during the token exchange process. It has been patched in Open WebUI version 0.11.0 via two separate commits. Users are strongly advised to upgrade immediately or disable the OAuth token exchange feature as a mitigation.
Technical details
Mitigation steps:
Affected products:
Open WebUI 0.8.0
Open WebUI 0.9.0
Open WebUI 0.10.0
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-70482
https://github.com/open-webui/open-webui/commit/b190dcf3caa00dc8b7b9c7312828298d9143f60d
https://github.com/open-webui/open-webui/commit/c4332be71e6e9c314e8a13b9d2819a6932561630
https://github.com/open-webui/open-webui/releases/tag/v0.11.0
https://github.com/open-webui/open-webui/security/advisories/GHSA-rq84-p6rr-vf89
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
