Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.41 until 0.11.1, get_user_by_oauth_sub and get_user_by_scim_external_id in backend/open_webui/models/users.py used JSON contains matching that compiled to SQL LIKE substring matching on SQLite. An OAuth subject containing percent or underscore wildcard characters could resolve to a different stored identity, potentially selecting an administrator account and issuing the attacker that account's session; PostgreSQL deployments were not affected. This issue is fixed in version 0.11.1.
Metrics
Affected Vendors & Products
References
History
Wed, 09 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.41 until 0.11.1, get_user_by_oauth_sub and get_user_by_scim_external_id in backend/open_webui/models/users.py used JSON contains matching that compiled to SQL LIKE substring matching on SQLite. An OAuth subject containing percent or underscore wildcard characters could resolve to a different stored identity, potentially selecting an administrator account and issuing the attacker that account's session; PostgreSQL deployments were not affected. This issue is fixed in version 0.11.1. | |
| Title | Open WebUI: Sign-in as another user via wildcard characters in the OAuth subject claim on SQLite | |
| Weaknesses | CWE-155 CWE-287 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-09-09T21:21:43.877Z
Updated: 2026-09-09T21:21:43.877Z
Reserved: 2026-09-08T16:44:23.783Z
Link: CVE-2026-87016
No data.
Status : Received
Published: 2026-09-09T22:18:46.720
Modified: 2026-09-09T22:18:46.720
Link: CVE-2026-87016
No data.