CVE-2024-56323Medium▾ SunlitOpenFGA Authorization Bypass
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.4%
OpenFGA v1.3.8 to v1.8.2 (Helm chart openfga-0.1.38 to openfga-0.2.19, docker v1.3.8 to v.1.8.2) are vulnerable to authorization bypass when certain Check and ListObject calls are executed.
You are affected by this authorization bypass vulnerability if you are using OpenFGA v1.3.8 to v1.8.2, specifically under the following conditions:
OPENFGA_CHECK_QUERY_CACHE_ENABLED), andUpgrade to v1.8.3. This upgrade is backwards compatible.
github.com/openfga/openfga >= 1.3.8, < 1.8.3Upgrade to a patched release:
github.com/openfga/openfga 1.8.3Connected by shared product, vendor, weakness, or advisory.
CVE-2023-43645Medium· 5.9OpenFGA Vulnerable to DoS from circular relationship definitions
CVE-2025-64751MediumOpenFGA Improper Policy Enforcement
CVE-2026-41131Medium· 5.0OpenFGA has Improper Policy Enforcement
CVE-2026-48096Medium· 5.0OpenFGA has cache-key delimiter injection in shared-iterator and v2 iterator that caches enables intra-store authorization-decision poiso…
CVE-2026-61709Medium· 5.3OpenFGA is an authorization and permission engine built for developers
CVE-2026-55689Medium· 6.8OpenFGA: OIDC audience validation skipped when --authn-oidc-audience is unset