CVE-2026-41131Medium· 5.0▾ SunlitOpenFGA has Improper Policy Enforcement
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 9.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
0.1%
Last analysed / modified upstream
5 → —
medium → none
— → 5
none → medium
5 → —
medium → none
— → 5
none → medium
5 → —
medium → none
— → 5
none → medium
In OpenFGA, in specific scenarios, models using conditions with caching enabled can result in two different check requests producing the same cache key. This could result in OpenFGA reusing an earlier cached result for a subsequent request.
Users are affected if their applications meet the following preconditions:
Upgrade to OpenFGA v1.14.1.
OpenFGA would like to thank @bugbunny-research for the detailed report.
github.com/openfga/openfga < 1.14.1Upgrade to a patched release:
github.com/openfga/openfga 1.14.1Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2024-56323MediumOpenFGA Authorization Bypass
CVE-2023-43645Medium· 5.9OpenFGA Vulnerable to DoS from circular relationship definitions
CVE-2025-64751MediumOpenFGA Improper Policy Enforcement
CVE-2026-48096Medium· 5.0OpenFGA has cache-key delimiter injection in shared-iterator and v2 iterator that caches enables intra-store authorization-decision poiso…
CVE-2026-61709Medium· 5.3OpenFGA is an authorization and permission engine built for developers
CVE-2026-55689Medium· 6.8OpenFGA: OIDC audience validation skipped when --authn-oidc-audience is unset