Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-wjwr-xfp9-r66p | Open WebUI: Admin demoted through SSO role sync keeps read and write access to all users' notes |
Thu, 10 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 10 Sep 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Open-webui
Open-webui open-webui |
|
| Vendors & Products |
Open-webui
Open-webui open-webui |
Wed, 09 Sep 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.1, role synchronization in backend/open_webui/routers/auths.py and backend/open_webui/utils/oauth.py updated an administrator's database role without invalidating the user record cached by backend/open_webui/socket/main.py. An administrator demoted through a trusted role header or OAuth role mapping could keep an already-open Socket.IO connection and continue reading or editing every user's collaborative notes until that connection closed. This issue is fixed in version 0.11.1. | |
| Title | Open WebUI: Admin demoted through SSO role sync keeps read and write access to all users' notes | |
| Weaknesses | CWE-613 CWE-863 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-10T17:57:17.765Z
Reserved: 2026-09-08T16:44:23.783Z
Link: CVE-2026-87014
Updated: 2026-09-10T17:56:59.645Z
Status : Undergoing Analysis
Published: 2026-09-09T21:17:06.327
Modified: 2026-09-10T18:18:10.760
Link: CVE-2026-87014
No data.
OpenCVE Enrichment
Updated: 2026-09-10T12:30:07Z
Github GHSA