{"id":"CVE-2026-34972","title":"github.com/openfga/openfga: OpenFGA: Improper policy enforcement via specific BatchCheck calls (CVE-2026-34972)","summary":"A flaw was found in OpenFGA, a high-performance authorization engine. Under specific conditions, a user making BatchCheck calls with multiple checks for the same object, relation, and user combination can trigger improper policy enforcemen…","severity":"medium","cvss":4.2,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","cvssSource":"vendor","cwe":"CWE-639","vendor":"Red Hat","product":"Multicluster Global Hub","affected":["multicluster_global_hub","advanced_cluster_management_for_kubernetes 2","ceph_storage 6"],"patched":["github.com/openfga/openfga 1.14.0"],"published":"2026-04-06","updated":"2026-09-18","sourceUpdated":"2026-09-18T18:32:38+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34972.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34972.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-34972"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2455611"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-34972"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34972"},{"url":"https://github.com/openfga/openfga/security/advisories/GHSA-jwvj-g8pc-cx45"}],"tags":["csaf","vex","red-hat","osv","go"],"epss":0.00211,"epssPercentile":0.11631,"aliases":["GO-2026-5483","GHSA-jwvj-g8pc-cx45"],"ecosystem":"go","ingestedAt":"2026-07-09T18:56:37.228Z","slug":"CVE-2026-34972","body":"## Overview\n\nA flaw was found in OpenFGA, a high-performance authorization engine. Under specific conditions, a user making BatchCheck calls with multiple checks for the same object, relation, and user combination can trigger improper policy enforcement. This can lead to incorrect authorization decisions, potentially allowing unauthorized access to resources or actions.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · affected: Multicluster Global Hub, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Ceph Storage 6 · no fix planned: Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Ceph Storage 6, Multicluster Global Hub · updated 2026-09-18 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34972.json)\n\n**github.com/openfga/openfga: OpenFGA: Improper policy enforcement via specific BatchCheck calls** — rated Moderate by Red Hat. Released 2026-04-06, updated 2026-09-18.\n\nAffected:\n\n- Multicluster Global Hub\n- Red Hat Advanced Cluster Management for Kubernetes 2\n- Red Hat Ceph Storage 6\n\nNo fix planned:\n\n- Red Hat Advanced Cluster Management for Kubernetes 2\n- Red Hat Ceph Storage 6\n- Multicluster Global Hub\n\n## Remediation\n\nFix deferred\n\nWorkarounds / mitigations:\n\n- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.\n\n## Package advisory (CVE-2026-34972)\n\nAffected packages:\n\n- `github.com/openfga/openfga >= 1.8.0, < 1.14.0`\n\nPatched in:\n\n- `github.com/openfga/openfga 1.14.0`\n\nSource: https://osv.dev/vulnerability/GO-2026-5483","depth":"sunlit","depthScore":23,"depthScoreParts":{"impact":23.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":208133,"id":"CVE-2026-34972","ts":1789922722706,"field":"cvss","old":null,"new":"4.2"},{"seq":208132,"id":"CVE-2026-34972","ts":1789922722706,"field":"severity","old":"none","new":"medium"}]}