Skip to content
archivevulnerability · 10 Sep 2026 · 21:23 UTC

GHSA-wpmr-8h3q-fwj7: Open WebUI: Sign-in as another user via wildcard characters in the OAuth subject claim on SQLite

VULNCVE-2026-87016source · GTH
HIGHHigh-risk vulnerability — CVSS 8.1

last 60 dispatches · spectrum

## Summary On SQLite deployments, the lookup that maps an external identity to a local account does a substring match instead of an exact match. A subject value containing SQL wildcard characters therefore matches accounts the value was never issued for, and the sign-in binds to whichever account the database returns first, which can be an administrator. The same defect affects SCIM external-ID resolution. PostgreSQL deployments are not affected, because they take a separate and correct code path. ## Preconditions * The database is SQLite. This is the default backend. …

CVE · detail
grounded ✓primary source ↗
Early access

Get the next one first.

Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.

bot-protected