vulns.co
/
GKData.io MCP

Open WebUI · 1 min read

Open WebUI: credentials must bind to their destination connection

CVE-2026-87015 concerns late-bound connection state: tool callables retained their own headers but read a shared cookie variable after connection processing finished. A maintainer-described controlled observation confirmed unintended session-cookie forwarding. Connection-specific authentication choice therefore failed to constrain the credentials crossing an integration boundary.

Open the reference Maintainer AdvisoryReviewed 2026-10-03

How to use this reference

Editorial lesson: treat destination, headers and cookies as one immutable request-authority context. Review capture semantics independently of configuration correctness. The advisory identifies 0.11.1 as fixed by binding cookies per connection. Credential isolation should survive changes in connection order.

Before reading

  • HTTP credentials, integration boundaries and secure data handling

Context and limits

  • Affected versions are >=0.6.27 and <0.11.1. Requires multiple attached tool servers, including a session/system-OAuth connection; exposure depends on shared-state capture during connection processing. Tool servers are not configured by default.
  • The recipient is an administrator-registered, partially trusted server. Impersonation, including administrator access, is a stated consequence of session-token disclosure; production compromise is not established.
  • Classic298 is credited as reporter. Patch-release date is not established here.

Sources and provenance

  1. A user's session cookies are sent to tool servers configured for bearer authentication Open WebUI · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software