PT-2026-48462 · Openfga · Openfga

Published

2026-06-10

·

Updated

2026-06-10

·

CVE-2026-48096

CVSS v3.1

5.0

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
OpenFGA is an authorization/permission engine built for developers. Prior to version 1.16.0, when iterator caching is enabled, two distinct check requests can produce the same cache key, leading to OpenFGA reusing an earlier cached result for a subsequent request. This issue has been patched in version 1.16.0.

Fix

Insufficient Verification of Data Authenticity

Exposure of Resource to Wrong Sphere

Weakness Enumeration

Related Identifiers

CVE-2026-48096

Affected Products

Openfga