Authorization Engine Vulnerability in OpenFGA
CVE-2026-41131

5MEDIUM

Key Information:

Vendor

Openfga

Status
Vendor
CVE Published:
21 April 2026

What is CVE-2026-41131?

OpenFGA, a permission management engine designed for developers, has a vulnerability that arises in certain scenarios when models employ conditions with caching enabled. Specifically, when relationships in a model depend on condition evaluations and caching is activated, simultaneous check requests may generate identical cache keys. This situation can lead to OpenFGA reusing an outdated cached result for a new request, compromising the integrity of authorization checks. Version 1.14.1 of OpenFGA addresses this issue, reinforcing the vendor's commitment to securing their products.

Affected Version(s)

openfga < 1.14.1

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.