CVE-2026-55170Low▾ SunlitOpenFGA Improper Policy Enforcement
▾ Sunlit zone — Low / medium · no exploitation signal
impact 13.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 10.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
0.3%
In OpenFGA, when MySQL is being used as the datastore, two distinct check requests can return the same response.
This applies if the following preconditions are met:
Upgrade to OpenFGA 1.18.0 or greater.
OpenFGA would like to thank @sahajamoth for the detailed report.
github.com/openfga/openfga < 1.18.0Upgrade to a patched release:
github.com/openfga/openfga 1.18.0Connected by shared product, vendor, weakness, or advisory.
CVE-2024-56323MediumOpenFGA Authorization Bypass
CVE-2023-43645Medium· 5.9OpenFGA Vulnerable to DoS from circular relationship definitions
CVE-2025-64751MediumOpenFGA Improper Policy Enforcement
CVE-2026-41131Medium· 5.0OpenFGA has Improper Policy Enforcement
CVE-2026-48096Medium· 5.0OpenFGA has cache-key delimiter injection in shared-iterator and v2 iterator that caches enables intra-store authorization-decision poiso…
CVE-2026-55689Medium· 6.8OpenFGA: OIDC audience validation skipped when --authn-oidc-audience is unset