GHSA-wpmr-8h3q-fwj7: Open WebUI: Sign-in as another user via wildcard characters in the OAuth subject claim on SQLite
HIGHHigh-risk vulnerability — CVSS 8.1
## Summary On SQLite deployments, the lookup that maps an external identity to a local account does a substring match instead of an exact match. A subject value containing SQL wildcard characters therefore matches accounts the value was never issued for, and the sign-in binds to whichever account the database returns first, which can be an administrator. The same defect affects SCIM external-ID resolution. PostgreSQL deployments are not affected, because they take a separate and correct code path. ## Preconditions * The database is SQLite. This is the default backend. …
CVE · detail
- CVE-2026-87016nvd ↗EPSS 0.35%
Early access
Get the next one first.
Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.
bot-protected