CVE-2026-87015 PUBLISHED

Open WebUI: A user's session cookies are sent to tool servers configured for bearer authentication

Assigner: GitHub_M
Reserved: 08.09.2026 Published: 09.09.2026 Updated: 09.09.2026

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.27 until 0.11.1, backend/open_webui/utils/tools.py captured a cookie jar from the enclosing connection loop instead of binding it to each external tool callable. When multiple tool servers were attached and a session or system OAuth connection was processed last, a request to a different server configured for bearer authentication could include the calling user's Open WebUI session cookies, allowing that server's operator to reuse the session and take over the account. This issue is fixed in version 0.11.1.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
CVSS Score: 6.8

Product Status

Vendor open-webui
Product open-webui
Versions
  • Version >= 0.6.27, < 0.11.1 is affected

References

Problem Types

  • CWE-201: Insertion of Sensitive Information Into Sent Data CWE