What is CVE-2026-70482?
In Open WebUI AI platform, when ENABLE_OAUTH_TOKEN_EXCHANGE is set to True, the /oauth/{provider}/token/exchange endpoint accepts a raw provider access token and validates it by calling the provider userinfo endpoint without proper verification. This affects versions from 0.8.0 to 0.11.0 and could allow unauthorized access via token exchange. An immediate update to the latest version is required to remediate this vulnerability.
Azərbaycanca: Open WebUI AI platformunda ENABLE_OAUTH_TOKEN_EXCHANGE aktiv olduqda, /oauth/{provider}/token/exchange endpoint-i xam provider access token-i düzgün yoxlamadan qəbul edir. 0.8.0-dən 0.11.0 versiyasına qədər təsir göstərən bu boşluq zərərli şəxslərə token mübadiləsi vasitəsilə icazəsiz giriş əldə etməyə imkan yarada bilər. Bu CVE-ni aradan qaldırmaq üçün dərhal ən son versiyaya yeniləmə tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
Which versions of Open WebUI are affected by CVE-2026-70482?
This vulnerability affects Open WebUI installations from version 0.8.0 to 0.11.0.
What is the primary remediation recommended for CVE-2026-70482?
An immediate update to the latest version is required to remediate this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.