Local UI security
Open WebUI discloses 16 CVEs in one batch; OAuth session-hijack flaw rates CVSS 8.1
Sixteen CVEs against Open WebUI 0.6.41–0.11.1 were published on September 9–10, led by CVE-2026-87016 (CVSS 8.1): an OAuth/SCIM identity-confusion bug where a 'sub' claim containing % or _ SQL wildcards can hijack an administrator's session on SQLite-backed deployments. PostgreSQL installs are unaffected. All 16 are fixed in v0.11.1, which shipped August 25 with security details deliberately withheld — anyone self-hosting Open WebUI should upgrade.



