By vendor
Openfga vulnerabilities
Known CVEs affecting Openfga products, prioritized by severity, with SEC.co remediation and detection guidance.
1 published vulnerability
- CVE-2026-48096MEDIUM 5.0
OpenFGA, an authorization engine used by developers to control permissions, has a caching flaw that could cause it to reuse incorrect permission decisions. When iterator caching is enabled, two different permission requests can accidentally use the same cached result, potentially allowing or denying access incorrectly. The issue affects versions before 1.16.0 and has been patched.