CVE-2026-34972Medium· 4.2▾ SunlitA flaw was found in OpenFGA, a high-performance authorization engine. Under specific conditions, a user making BatchCheck calls with multiple checks for the same object, relation, and user combination can trigger improper policy enforcemen…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 9.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.2%
Last analysed / modified upstream
— → 4.2
none → medium
A flaw was found in OpenFGA, a high-performance authorization engine. Under specific conditions, a user making BatchCheck calls with multiple checks for the same object, relation, and user combination can trigger improper policy enforcement. This can lead to incorrect authorization decisions, potentially allowing unauthorized access to resources or actions.
github.com/openfga/openfga: OpenFGA: Improper policy enforcement via specific BatchCheck calls — rated Moderate by Red Hat. Released 2026-04-06, updated 2026-09-18.
Affected:
No fix planned:
Fix deferred
Workarounds / mitigations:
Affected packages:
github.com/openfga/openfga >= 1.8.0, < 1.14.0Patched in:
github.com/openfga/openfga 1.14.0Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2024-1313Medium· 6.5grafana: vulnerable to authorization bypass (CVE-2024-1313)
CVE-2026-44283Medium· 4.3etcd: etcd: Authenticated user can bypass RBAC for unauthorized data access (CVE-2026-44283)
CVE-2026-18620High· 7.1A flaw was found in Data Science Pipelines
CVE-2026-37236Critical· 9.8grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control
CVE-2026-17527High· 7.7In containerized-data-importer (CDI), the aggregated cdi.kubevirt.io:view ClusterRole, intended to provide read-only access to CDI resources, includes a rule granting create on the datavolumes/source subresource
CVE-2026-19130Medium· 5.8A flaw was found in the provider-credential-controller component of multicluster-engine (MCE)