Back

MEDIUM

Open WebUI: Admin demoted through SSO role sync keeps read and write access to all users' notes

Published Sep 9, 2026

Description

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.1, role synchronization in backend/open_webui/routers/auths.py and backend/open_webui/utils/oauth.py updated an administrator's database role without invalidating the user record cached by backend/open_webui/socket/main.py. An administrator demoted through a trusted role header or OAuth role mapping could keep an already-open Socket.IO connection and continue reading or editing every user's collaborative notes until that connection closed. This issue is fixed in version 0.11.1.

Affected products

Remediation

No remediation recorded yet.

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Sep 9, 2026
Updated Sep 10, 2026
Reserved Sep 8, 2026
CISA Vulnrichment
Updated Sep 10, 2026
NVD
Status Analyzed
Modified Sep 15, 2026
Red Hat
Severity n/a
Public date n/a
GHSA-WJWR-XFP9-R66P