Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-87014

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.1, role synchronization in backend/open_webui/routers/auths.py and backend/open_webui/utils/oauth.py updated an administrator's database role without invalidating the user record cached by backend/open_webui/socket/main.py. An administrator demoted through a trusted role header or OAuth role mapping could keep an already-open Socket.IO connection and continue reading or editing every user's collaborative notes until that connection closed. This issue is fixed in version 0.11.1.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 20.2%
CVSS Severity
CVSS v3 Score 6.5
Products affected by CVE-2026-87014


Contact Us

Shodan ® - All rights reserved