OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. From 1.8.0 to 1.13.1, under specific conditions, BatchCheck calls with multiple checks sent for the same object, relation, and user combination can result in improper policy enforcement. This vulnerability is fixed in 1.14.0.
Metrics
Affected Vendors & Products
References
History
Tue, 07 Apr 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. From 1.8.0 to 1.13.1, under specific conditions, BatchCheck calls with multiple checks sent for the same object, relation, and user combination can result in improper policy enforcement. This vulnerability is fixed in 1.14.0. | |
| Title | OpenFGA's BatchCheck within-request deduplication produces incorrect authorization decisions via list-value cache-key collision | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-06T20:41:33.414Z
Reserved: 2026-03-31T19:38:31.616Z
Link: CVE-2026-34972
No data.
Status : Received
Published: 2026-04-06T21:16:19.997
Modified: 2026-04-06T21:16:19.997
Link: CVE-2026-34972
No data.
OpenCVE Enrichment
No data.