Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 09 Sep 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.1, role synchronization in backend/open_webui/routers/auths.py and backend/open_webui/utils/oauth.py updated an administrator's database role without invalidating the user record cached by backend/open_webui/socket/main.py. An administrator demoted through a trusted role header or OAuth role mapping could keep an already-open Socket.IO connection and continue reading or editing every user's collaborative notes until that connection closed. This issue is fixed in version 0.11.1. | |
| Title | Open WebUI: Admin demoted through SSO role sync keeps read and write access to all users' notes | |
| Weaknesses | CWE-613 CWE-863 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-09T21:01:39.505Z
Reserved: 2026-09-08T16:44:23.783Z
Link: CVE-2026-87014
No data.
Status : Received
Published: 2026-09-09T21:17:06.327
Modified: 2026-09-09T21:17:06.327
Link: CVE-2026-87014
No data.
OpenCVE Enrichment
No data.