PT-2026-50974 · Openfga · Openfga
Published
2026-06-19
·
Updated
2026-06-25
·
CVE-2026-55689
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
OpenFGA versions prior to 1.18.0
Description
The OIDC authenticator fails to validate the JWT audience (
aud) claim when no audience is configured. In environments where a single identity provider issues tokens for multiple services, a token intended for a different service could be used to authenticate to OpenFGA. This occurs when authn.method is set to oidc and authn.oidc.issuer is configured without setting the authn.oidc.audience variable.Recommendations
Upgrade to version 1.18.0 or greater.
Ensure both
authn.oidc.issuer and authn.oidc.audience are configured to enable proper validation.Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openfga