PT-2026-50974 · Openfga · Openfga

CVE-2026-55689

·

Published

2026-06-19

·

Updated

2026-07-30

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions OpenFGA versions prior to 1.18.0
Description The OIDC authenticator fails to validate the JWT audience (aud) claim when no audience is configured. In environments where a single identity provider issues tokens for multiple services, a token intended for a different service could be used to authenticate to OpenFGA. This occurs when authn.method is set to oidc and authn.oidc.issuer is configured without setting the authn.oidc.audience variable.
Recommendations Upgrade to version 1.18.0 or greater. Ensure both authn.oidc.issuer and authn.oidc.audience are configured to enable proper validation.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CLEANSTART-2026-LC55153
CVE-2026-55689
GHSA-HCXC-WF8J-23HV
GO-2026-5423
OPENSUSE-SU-2026:21483-1

Affected Products

Openfga