Authorization Misconfiguration in SpiceDB Database System
CVE-2026-55866

3.7LOW

Key Information:

Vendor

Authzed

Status
Vendor
CVE Published:
14 September 2026

What is CVE-2026-55866?

A flaw in the SpiceDB permission management system can result in erroneous permission evaluations. Specifically, during the processing of authorization checks, the system may return incorrect permission results due to the omission of CheckHints in its cache key construction. This can lead to a scenario where a permission check might yield a 'granted' outcome even when it should not, particularly in complex permission scenarios involving multiple branches of permission checks. This issue is addressed in version 1.54.0, where improvements ensure that such cache poisoning vulnerabilities are effectively mitigated.

Affected Version(s)

spicedb >= 1.34.1, < 1.54.0

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.