PT-2026-32978 · Openfga · Openfga

·

CVE-2026-40293

·

Published

2026-04-08

·

Updated

2026-07-30

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenFGA versions 0.1.4 through 1.13.1
Description When configured to use preshared-key authentication with the built-in playground enabled, the local server includes the preshared API key in the HTML response of the '/playground' endpoint. This endpoint is enabled by default and does not require authentication, as it is intended for local development and debugging rather than production environments. The issue affects instances running with the --authn-method set to preshared, where the playground is enabled and accessible beyond localhost or trusted networks.
Recommendations Upgrade to OpenFGA version 1.14.0. Disable the playground by running ./openfga run --playground-enabled=false.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-40293
GHSA-68M9-983M-F3V5
GO-2026-5170
OPENSUSE-SU-2026:21483-1

Affected Products

Openfga