CVE-2026-48096

OpenFGA is an authorization/permission engine built for developers. Prior to version 1.16.0, when iterator caching is enabled, two distinct check requests can produce the same cache key, leading to OpenFGA reusing an earlier cached result for a subsequent request. This issue has been patched in version 1.16.0.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:openfga:helm_charts:*:*:*:*:*:openfga:*:*
cpe:2.3:a:openfga:openfga:*:*:*:*:*:*:*:*

History

12 Jun 2026, 00:46

Type Values Removed Values Added
References () https://github.com/openfga/openfga/releases/tag/v1.16.0 - () https://github.com/openfga/openfga/releases/tag/v1.16.0 - Product, Release Notes
References () https://github.com/openfga/openfga/security/advisories/GHSA-8396-jffm-qx4w - () https://github.com/openfga/openfga/security/advisories/GHSA-8396-jffm-qx4w - Vendor Advisory
CPE cpe:2.3:a:openfga:openfga:*:*:*:*:*:*:*:*
cpe:2.3:a:openfga:helm_charts:*:*:*:*:*:openfga:*:*
First Time Openfga
Openfga helm Charts
Openfga openfga

10 Jun 2026, 16:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-10 16:17

Updated : 2026-06-12 00:46


NVD link : CVE-2026-48096

Mitre link : CVE-2026-48096

CVE.ORG link : CVE-2026-48096


JSON object : View

Products Affected

openfga

  • openfga
  • helm_charts
CWE
CWE-345

Insufficient Verification of Data Authenticity

CWE-668

Exposure of Resource to Wrong Sphere