CVE-2026-87016 | open-webui Open WebUI up to 0.11.0 User Identity Resolution users.py improper authentication

SecurityVulns

A vulnerability marked as critical has been reported in open-webui Open WebUI up to 0.11.0. Affected is the function get_user_by_oauth_sub/get_user_by_scim_external_id of the file backend/open_webui/models/users.py of the component User Identity Resolution. Performing a manipulation results in improper authentication.

This vulnerability is known as CVE-2026-87016. Remote exploitation of the attack is possible. No exploit is available.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More