PT-2026-48462 · Openfga · Openfga

CVE-2026-48096

·

Published

2026-06-10

·

Updated

2026-07-30

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenFGA versions prior to 1.16.0
Description When iterator caching is enabled, specifically with SharedIteratorCache and ListObjectsIteratorCache, two distinct check requests can produce the same cache key. This causes the system to reuse a previously cached result for a subsequent, different request.
Recommendations Upgrade to version 1.16.0 or greater. As a temporary workaround, consider disabling SharedIteratorCache and ListObjectsIteratorCache to prevent cache key collisions.

Exploit

Fix

Insufficient Verification of Data Authenticity

Exposure of Resource to Wrong Sphere

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CLEANSTART-2026-GX27419
CLEANSTART-2026-IE49312
CLEANSTART-2026-LC55153
CLEANSTART-2026-ZZ38071
CVE-2026-48096
GHSA-8396-JFFM-QX4W
GO-2026-5239
OPENSUSE-SU-2026:21483-1

Affected Products

Openfga