← volver
CVE-2026-34972

OpenFGA's BatchCheck within-request deduplication produces incorrect authorization decisions via list-value cache-key collision

CVSS 5 MEDIUMEPSS 0.2%CWE-863
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 5EPSS 0.2%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
06 abr 2026Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. From 1.8.0 to 1.13.1, under specific conditions, BatchCheck calls with multiple checks sent for the same object, relation, and user combination can result in improper policy enforcement. This vulnerability is fixed in 1.14.0.
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
Productos afectados
openfga · openfga

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →