Session Cookie Vulnerability in Open WebUI by Open WebUI
CVE-2026-87015

6.8MEDIUM

Key Information:

Vendor

Open-webui

Vendor
CVE Published:
9 September 2026

What is CVE-2026-87015?

Open WebUI is a self-hosted AI tool that experienced a session management issue affecting versions 0.6.27 through 0.11.1. This vulnerability is rooted in the handling of cookies during external tool calls. Specifically, session cookies could be inadvertently shared across different tool servers when a user's session was processed last. As a result, an attacker operating another server could exploit this flaw to hijack user sessions and gain unauthorized access to accounts. This issue has been addressed in version 0.11.1.

Affected Version(s)

open-webui >= 0.6.27, < 0.11.1

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.