
CVE-2026-70482 Open WebUI OAuth token-exchange bypass could let attackers convert a raw provider access token into a full Open WebUI session where token exchange is enabled Full analysis: https://github.com/alan-turing-institute/cyber-threat-observatory/blob/main/reports/2026-08-04/TIER_2_CVE-2026-70482.md #CyberSecurity #IdentitySecurity #VulnerabilityManagement
Post summary
The post announces an OAuth token‑exchange bypass in Open WebUI, allowing attackers to upgrade a raw access token into a full session, and provides a link to a detailed analysis, but no PoC, exploit, or patch is mentioned.
