{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/open-webui--0.9.0--0.10.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:openwebui:open_webui:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.1,"id":"CVE-2026-59219"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Open WebUI (\u003e= 0.9.0, \u003c 0.10.0)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","jwt","authentication","webui","realtime","bypass"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eOpen WebUI versions between 0.9.0 and 0.10.0 (exclusive), specifically when configured to use Redis for token management, contain a critical vulnerability identified as CVE-2026-59219. This flaw prevents proper JWT revocation enforcement on the application's realtime communication channels, including Socket.IO connections and terminal websockets. While the HTTP REST API correctly rejects tokens that have been invalidated by user sign-out or OIDC back-channel logout, the realtime endpoints only verify token signature and expiry, neglecting to check the revocation status in Redis. This oversight allows an attacker who has compromised a user's JWT to retain unauthorized access to sensitive realtime functionalities, such as collaborative notes, chat messages, and potentially terminal sessions, even after the legitimate user has taken steps to revoke the token, thereby bypassing a crucial security measure designed to mitigate the impact of stolen credentials. The vulnerability affects installations configured with Redis for JWT revocation.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker compromises a legitimate user's JSON Web Token (JWT) for Open WebUI.\u003c/li\u003e\n\u003cli\u003eThe legitimate user signs out from Open WebUI, or their Identity Provider initiates an OIDC back-channel logout.\u003c/li\u003e\n\u003cli\u003eOpen WebUI's Redis instance correctly records the compromised JWT as revoked and updates the user's \u003ccode\u003erevoked_at\u003c/code\u003e timestamp.\u003c/li\u003e\n\u003cli\u003eThe attacker attempts to use the revoked JWT to access Open WebUI's HTTP REST API endpoints; these attempts are correctly denied with a 401 Unauthorized error due to proper revocation checks.\u003c/li\u003e\n\u003cli\u003eThe attacker then initiates a new connection to one of Open WebUI's realtime endpoints, such as a Socket.IO connection (for chat, collaborative notes) or a terminal websocket.\u003c/li\u003e\n\u003cli\u003eThe attacker presents the previously revoked JWT to the realtime endpoint for authentication.\u003c/li\u003e\n\u003cli\u003eDue to CVE-2026-59219, the realtime endpoint's authentication logic only performs checks for token signature validity and expiry, but critically fails to consult the Redis revocation status.\u003c/li\u003e\n\u003cli\u003eThe attacker successfully authenticates to the realtime service, gaining unauthorized access to and control over features like reading channel messages, participating in collaborative notes, and accessing terminal sessions as the legitimate user, despite the token having been officially revoked.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe successful exploitation of CVE-2026-59219 allows an attacker to maintain unauthorized, persistent access to an Open WebUI user's realtime functionalities, even after the legitimate user has performed a sign-out or an OIDC back-channel logout has been processed. This bypasses the intended remediation for compromised tokens. Attackers can leverage this persistent access to join user, channel, and note rooms, receive realtime channel messages and collaborative note updates, drive socket-level collaboration, and pass authentication for terminal websockets. This can lead to sensitive information disclosure, unauthorized data manipulation in collaborative environments, and potential remote execution capabilities if terminal servers are configured, effectively allowing the attacker to impersonate the victim in realtime interactions.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2026-59219 immediately by upgrading all affected Open WebUI installations to version 0.10.0 or later.\u003c/li\u003e\n\u003cli\u003eEnsure that Open WebUI instances configured with Redis are updated, as the vulnerability only manifests in this configuration.\u003c/li\u003e\n\u003cli\u003eReview network logs for suspicious long-lived connections to Open WebUI's Socket.IO or websocket endpoints from IP addresses not associated with legitimate users, which could indicate a post-revocation bypass attempt.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-24T17:01:46Z","date_published":"2026-07-24T17:01:46Z","id":"https://feed.craftedsignal.io/briefs/2026-07-open-webui-jwt-revocation-bypass/","summary":"Open WebUI versions from 0.9.0 to before 0.10.0, when configured with Redis, fail to correctly enforce JWT revocation for realtime authentication endpoints such as Socket.IO and terminal websockets, allowing attackers to maintain access to real-time features with stolen, revoked JWTs.","title":"Open WebUI: Realtime Endpoints Fail to Revoke JWTs","url":"https://feed.craftedsignal.io/briefs/2026-07-open-webui-jwt-revocation-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Open WebUI (\u003e= 0.9.0, \u003c 0.10.0)","version":"https://jsonfeed.org/version/1.1"}