Session Cookie Vulnerability in Open WebUI by Open WebUI
CVE-2026-87015
6.8MEDIUM
What is CVE-2026-87015?
Open WebUI is a self-hosted AI tool that experienced a session management issue affecting versions 0.6.27 through 0.11.1. This vulnerability is rooted in the handling of cookies during external tool calls. Specifically, session cookies could be inadvertently shared across different tool servers when a user's session was processed last. As a result, an attacker operating another server could exploit this flaw to hijack user sessions and gain unauthorized access to accounts. This issue has been addressed in version 0.11.1.
Affected Version(s)
open-webui >= 0.6.27, < 0.11.1
