8.1

CVE-2026-55689

OpenFGA: OIDC audience validation skipped when --authn-oidc-audience is unset

OpenFGA is an authorization/permission engine built for developers. Prior to 1.18.0, OpenFGA's OIDC authenticator skipped JWT audience validation when authn.method was set to oidc, authn.oidc.issuer was configured, and authn.oidc.audience was not set, allowing a token minted for an unrelated service by the same identity provider to authenticate to OpenFGA. This issue is fixed in 1.18.0.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
OpenfgaHelm Charts SwPlatformopenfga Version < 0.3.9
OpenfgaOpenfga Version < 1.18.0
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.3% 0.22
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.1 2.8 5.2
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
security-advisories@github.com 6.8 1.6 5.2
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

https://github.com/openfga/helm-charts/releases/tag/openfga-0.3.9
Product
Release Notes
https://github.com/openfga/openfga/releases/tag/v1.18.0
Product
Release Notes
https://github.com/openfga/openfga/security/advisories/GHSA-hcxc-wf8j-23hv
Vendor Advisory
https://github.com/openfga/openfga/commit/44596773b2e62738720ef215bf7fa04352954271
Patch
https://github.com/openfga/helm-ch
Broken Link