CVE-2026-48096Medium· 5.0▾ SunlitOpenFGA has cache-key delimiter injection in shared-iterator and v2 iterator that caches enables intra-store authorization-decision poisoning
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 7.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
0.1%
Last analysed / modified upstream
In OpenFGA, when iterator caching is enabled, two distinct check requests can produce the same cache key, leading to OpenFGA reusing an earlier cached result for a subsequent request.
This applies if the following preconditions are present:
Upgrade to version 1.16.0 or greater.
OpenFGA would like to thank @j4xT for the discovery and the detailed report.
github.com/openfga/openfga < 1.16.0Upgrade to a patched release:
github.com/openfga/openfga 1.16.0Connected by shared product, vendor, weakness, or advisory.
CVE-2024-56323MediumOpenFGA Authorization Bypass
CVE-2023-43645Medium· 5.9OpenFGA Vulnerable to DoS from circular relationship definitions
CVE-2025-64751MediumOpenFGA Improper Policy Enforcement
CVE-2026-41131Medium· 5.0OpenFGA has Improper Policy Enforcement
CVE-2026-61709Medium· 5.3OpenFGA is an authorization and permission engine built for developers
CVE-2026-55689Medium· 6.8OpenFGA: OIDC audience validation skipped when --authn-oidc-audience is unset