OAuth Token Exchange Vulnerability in Open WebUI by Open WebUI
CVE-2026-70482

8.1HIGH

Key Information:

Vendor

Open-webui

Vendor
CVE Published:
4 August 2026

What is CVE-2026-70482?

Open WebUI, an extensible self-hosted AI platform, has a vulnerability in its OAuth token exchange functionality. When the ENABLE_OAUTH_TOKEN_EXCHANGE setting is enabled, versions 0.8.0 through 0.11.0 accept raw access tokens from various providers without verifying the associated OAuth client. This improper validation allows individuals with access tokens from any client linked to the same provider to gain unauthorized Open WebUI sessions, even with applications that the system administrator does not control. This security issue has been rectified in version 0.11.0.

Affected Version(s)

open-webui >= 0.8.0, < 0.11.0

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.