CVE-2026-87014 | open-webui Open WebUI up to 0.11.0 Role Synchronization auths.py improper synchronization
A vulnerability labeled as problematic has been found in open-webui Open WebUI up to 0.11.0. This impacts an unknown function of the file backend/open_webui/routers/auths.py of the component Role Synchronization. Such manipulation leads to improper synchronization.
This vulnerability is traded as CVE-2026-87014. The attack may be launched remotely. There is no exploit available.
The affected component should be upgraded.VulDB Recent EntriesRead More