---
id: CVE-2026-34972
title: >-
  github.com/openfga/openfga: OpenFGA: Improper policy enforcement via specific
  BatchCheck calls (CVE-2026-34972)
summary: >-
  A flaw was found in OpenFGA, a high-performance authorization engine. Under
  specific conditions, a user making BatchCheck calls with multiple checks for
  the same object, relation, and user combination can trigger improper policy
  enforcemen…
severity: medium
cvss: 4.2
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N'
cvssSource: vendor
cwe: CWE-639
vendor: Red Hat
product: Multicluster Global Hub
affected:
  - multicluster_global_hub
  - advanced_cluster_management_for_kubernetes 2
  - ceph_storage 6
patched:
  - github.com/openfga/openfga 1.14.0
published: '2026-04-06'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T18:32:38+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34972.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34972.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-34972'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2455611'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-34972'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-34972'
  - url: 'https://github.com/openfga/openfga/security/advisories/GHSA-jwvj-g8pc-cx45'
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - go
epss: 0.0027
epssPercentile: 0.17018
aliases:
  - GO-2026-5483
  - GHSA-jwvj-g8pc-cx45
ecosystem: go
ingestedAt: '2026-07-09T18:56:37.228Z'
---

## Overview

A flaw was found in OpenFGA, a high-performance authorization engine. Under specific conditions, a user making BatchCheck calls with multiple checks for the same object, relation, and user combination can trigger improper policy enforcement. This can lead to incorrect authorization decisions, potentially allowing unauthorized access to resources or actions.

## Vendor advisories

- **Red Hat VEX** · Moderate · affected: Multicluster Global Hub, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Ceph Storage 6 · no fix planned: Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Ceph Storage 6, Multicluster Global Hub · updated 2026-09-18 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34972.json)

**github.com/openfga/openfga: OpenFGA: Improper policy enforcement via specific BatchCheck calls** — rated Moderate by Red Hat. Released 2026-04-06, updated 2026-09-18.

Affected:

- Multicluster Global Hub
- Red Hat Advanced Cluster Management for Kubernetes 2
- Red Hat Ceph Storage 6

No fix planned:

- Red Hat Advanced Cluster Management for Kubernetes 2
- Red Hat Ceph Storage 6
- Multicluster Global Hub

## Remediation

Fix deferred

Workarounds / mitigations:

- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

## Package advisory (CVE-2026-34972)

Affected packages:

- `github.com/openfga/openfga >= 1.8.0, < 1.14.0`

Patched in:

- `github.com/openfga/openfga 1.14.0`

Source: https://osv.dev/vulnerability/GO-2026-5483
