CVE-2026-87014: Open WebUI: Admin demoted through SSO role sync keeps read and write access to all users' notes

Published Sep 9, 2026
·
Updated

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.1, role synchronization in backend/openwebui/routers/auths.py and backend/openwebui/utils/oauth.py updated an administrator's database role without invalidating the user record cached by backend/openwebui/socket/main.py. An administrator demoted through a trusted role header or OAuth role mapping could keep an already-open Socket.IO connection and continue reading or editing every user's collaborative notes until that connection closed. This issue is fixed in version 0.11.1.

Affected Software

1 affected component
Open WebUI Open WebUI>0.9.0<0.11.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Open WebUI to a version that resolves this vulnerability.

    Fixed in 0.11.1

Event History

Sep 9, 2026
CVE Published
via MITRE·09:01 PM
Data Sourced
via MITRE·09:01 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Instances running Open WebUI versions from 0.9.0 through 0.11.1 are affected when administrator roles are synchronized through a trusted role header or OAuth role mapping. The risk applies to administrators who are demoted while they already have an open Socket.IO connection.

2

What must happen for the former administrator to retain access?

The user must have an already-open Socket.IO connection at the time their administrator role is changed by role synchronization. They can then continue to read or edit all users' collaborative notes until that connection closes.

3

What can be done if upgrading is not immediately possible?

Ensure that Socket.IO connections belonging to a demoted administrator are closed. The retained access persists only until the existing connection closes.

4

How can I tell whether a user may still be affected after demotion?

A user may be affected if their role was demoted through a trusted role header or OAuth role mapping while they had an active Socket.IO connection. Their access should end when that connection closes.

5

Which version fixes the issue?

The issue is fixed in Open WebUI version 0.11.1.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203