CVE-2026-88006 | Open WebUI up to 0.11.0 OAuth Token Exchange Endpoint privileges management
A vulnerability classified as critical was found in Open WebUI up to 0.11.0. This vulnerability affects unknown code of the component OAuth Token Exchange Endpoint. The manipulation results in improper privilege management.
This vulnerability was named CVE-2026-88006. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is advised.VulDB Recent EntriesRead More