PT-2026-50974 · Openfga · Openfga
CVE-2026-55689
·
Published
2026-06-19
·
Updated
2026-07-30
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
OpenFGA versions prior to 1.18.0
Description
The OIDC authenticator fails to validate the JWT audience (
aud) claim when no audience is configured. In environments where a single identity provider issues tokens for multiple services, a token intended for a different service could be used to authenticate to OpenFGA. This occurs when authn.method is set to oidc and authn.oidc.issuer is configured without setting the authn.oidc.audience variable.Recommendations
Upgrade to version 1.18.0 or greater.
Ensure both
authn.oidc.issuer and authn.oidc.audience are configured to enable proper validation.Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openfga