8.1
CVE-2026-55689
- EPSS 0.3%
- Veröffentlicht 09.07.2026 21:06:22
- Zuletzt bearbeitet 14.07.2026 01:28:44
- CVE-Watchlists
- Unerledigt
OpenFGA: OIDC audience validation skipped when --authn-oidc-audience is unset
OpenFGA is an authorization/permission engine built for developers. Prior to 1.18.0, OpenFGA's OIDC authenticator skipped JWT audience validation when authn.method was set to oidc, authn.oidc.issuer was configured, and authn.oidc.audience was not set, allowing a token minted for an unrelated service by the same identity provider to authenticate to OpenFGA. This issue is fixed in 1.18.0.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Openfga ≫ Helm Charts SwPlatformopenfga Version < 0.3.9
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.3% | 0.22 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 8.1 | 2.8 | 5.2 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
|
| security-advisories@github.com | 6.8 | 1.6 | 5.2 |
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
https://github.com/openfga/helm-charts/releases/tag/openfga-0.3.9
https://github.com/openfga/openfga/releases/tag/v1.18.0
https://github.com/openfga/openfga/security/advisories/GHSA-hcxc-wf8j-23hv
https://github.com/openfga/openfga/commit/44596773b2e62738720ef215bf7fa04352954271
https://github.com/openfga/helm-ch