CVE-2026-88005

    Dashboard / Vulnerabilities / CVE-2026-88005

    CVE-2026-88005

    Published: 10 Sept 2026Last Modified: 11 Sept 2026

    Summary: Open WebUI: Users denied by the OAuth domain allowlist or role policy can still sign in via token exchange

    Details: Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.9.0, Open WebUI's OAuth token exchange endpoint issues a session for a provider access token without applying the email domain allowlist that the normal OAuth login callback enforces. An account whose email domain the login callback would refuse could still obtain a working session through this endpoint. This issue is fixed in version 0.9.0.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- 7a7a25766c3dc13fa85544a93d011e00b7c0b2b4

    Affected versions

    v0.8.12
    v0.8.11
    v0.8.10
    v0.8.9
    v0.8.8
    v0.8.7
    v0.8.6
    v0.8.5
    v0.8.4
    v0.8.3
    v0.8.2
    v0.8.1
    v0.8.0

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2026-88005 | CVE-DB