← voltar
CVE-2026-48096

OpenFGA: Cache-key delimiter injection in openfga/openfga shared-iterator and v2 iterator caches enables intra-store authorization-decision poisoning

CVSS 5 MEDIUMEPSS 0.1%CWE-345CWE-668
Vexday Risk Score
13Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 5EPSS 0.1%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
10 jun 2026Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
OpenFGA is an authorization/permission engine built for developers. Prior to version 1.16.0, when iterator caching is enabled, two distinct check requests can produce the same cache key, leading to OpenFGA reusing an earlier cached result for a subsequent request. This issue has been patched in version 1.16.0.
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
Produtos afetados
openfga · openfga

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →