{"id":"PYSEC-2026-3602","summary":"Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation","details":"**Title:** Scheduled automations continue after pending-user deactivation and stored model ACL revocation\n\n### Summary\n\nOpen WebUI documents `pending` as a zero-access role used for new sign-ups and deactivated users, and normal HTTP routes enforce that with `get_verified_user()` (which rejects `pending`), while automation create/update/run routes additionally require the `features.automations` permission. Two paths missed that lifecycle gate, so a deactivated (`pending`) account could keep acting through the background automation scheduler:\n\n1. **Scheduler did not re-gate the owner.** When a stored automation became due, `execute_automation()` rehydrated the owner with `Users.get_user_by_id(...)` and re-entered the chat completion pipeline without re-checking that the owner was still `user`/`admin` or still held `features.automations`. A still-active automation therefore kept running after its owner was deactivated.\n2. **Model ACL only enforced for exact role `user`.** `check_model_access()` applied private-model grants only when `user.role == \"user\"`, so a `pending` principal fell through a branch that denies a normal non-owner `user`.\n\nNet effect: a deactivated account could continue scheduled chat generation through the background worker, consuming the operator's configured model-provider credentials and reaching a stored automation model ID that its current role/ACL state would no longer permit through normal routes.\n\n### Impact\n\nA `pending`/deactivated account continues to execute due scheduled automations after its access has been revoked, consuming the operator's provider credentials, quota and shared capacity, and bypassing the private-model ACL for the automation's stored model ID. Exploitation requires a previously created active automation and a later transition to `pending` (deactivation or approval rollback), so it is bounded and not interactive. It does not grant unauthenticated access, account takeover, code execution, or cross-user data exfiltration.\n\n### Patched\n\nIn 0.10.0:\n\n- `execute_automation()` aborts and records an error unless the rehydrated owner is still `user` or `admin` and (for non-admins) still holds `features.automations`, so a deactivated or de-permissioned owner's due automation no longer runs.\n- `check_model_access()` enforces model ACLs for every non-admin role rather than only the exact role `user`, so a `pending` or otherwise unrecognised role no longer falls through.\n\n### Credits\n\n@rexpository","aliases":["CVE-2026-59226","GHSA-mvx4-532p-xfm9"],"modified":"2026-08-04T14:30:28.965011814Z","published":"2026-08-04T11:34:42.461003Z","references":[{"type":"WEB","url":"https://github.com/open-webui/open-webui/security/advisories/GHSA-mvx4-532p-xfm9"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59226"},{"type":"WEB","url":"https://github.com/open-webui/open-webui/pull/26047"},{"type":"WEB","url":"https://github.com/open-webui/open-webui/commit/920b655f4689e2118de928fbc936f6ebd4fed396"},{"type":"PACKAGE","url":"https://github.com/open-webui/open-webui"},{"type":"WEB","url":"https://github.com/open-webui/open-webui/releases/tag/v0.10.0"},{"type":"PACKAGE","url":"https://pypi.org/project/open-webui"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-mvx4-532p-xfm9"}],"affected":[{"package":{"name":"open-webui","ecosystem":"PyPI","purl":"pkg:pypi/open-webui"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0.9.0"},{"fixed":"0.10.0"}]}],"versions":["0.9.0","0.9.1","0.9.2","0.9.3","0.9.4","0.9.5","0.9.6"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/open-webui/PYSEC-2026-3602.yaml"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L"}]}