8.1

CVE-2026-55689

OpenFGA: OIDC audience validation skipped when --authn-oidc-audience is unset

OpenFGA is an authorization/permission engine built for developers. Prior to 1.18.0, OpenFGA's OIDC authenticator skipped JWT audience validation when authn.method was set to oidc, authn.oidc.issuer was configured, and authn.oidc.audience was not set, allowing a token minted for an unrelated service by the same identity provider to authenticate to OpenFGA. This issue is fixed in 1.18.0.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Openfga ≫ Helm Charts SwPlatform openfga Version < 0.3.9
Openfga ≫ Openfga Version < 1.18.0
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.3% 0.22
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.1 2.8 5.2
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
security-advisories@github.com 6.8 1.6 5.2
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

https://github.com/openfga/helm-charts/releases/tag/openfga-0.3.9
Product
Release Notes
https://github.com/openfga/openfga/releases/tag/v1.18.0
Product
Release Notes
https://github.com/openfga/openfga/security/advisories/GHSA-hcxc-wf8j-23hv
Vendor Advisory
https://github.com/openfga/openfga/commit/44596773b2e62738720ef215bf7fa04352954271
Patch
https://github.com/openfga/helm-ch
Broken Link