Authorization Misconfiguration in SpiceDB Database System
CVE-2026-55866
3.7LOW
What is CVE-2026-55866?
A flaw in the SpiceDB permission management system can result in erroneous permission evaluations. Specifically, during the processing of authorization checks, the system may return incorrect permission results due to the omission of CheckHints in its cache key construction. This can lead to a scenario where a permission check might yield a 'granted' outcome even when it should not, particularly in complex permission scenarios involving multiple branches of permission checks. This issue is addressed in version 1.54.0, where improvements ensure that such cache poisoning vulnerabilities are effectively mitigated.
Affected Version(s)
spicedb >= 1.34.1, < 1.54.0
