CVE-2026-48096 Details
Description
OpenFGA is an authorization/permission engine built for developers. Prior to version 1.16.0, when iterator caching is enabled, two distinct check requests can produce the same cache key, leading to OpenFGA reusing an earlier cached result for a subsequent request. This issue has been patched in version 1.16.0.
A vulnerability exists in OpenFGA versions prior to 1.16.0, specifically when iterator caching is enabled. In this scenario, two separate check requests can generate the same cache key, causing OpenFGA to incorrectly reuse a previously cached result for a later request. This issue has been addressed in version 1.16.0.
Users can upgrade to OpenFGA version 1.16.0 or later to address this vulnerability. For those using OpenFGA Helm charts, version 0.3.5 is recommended.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/openfga/openfga/releases/tag/v1.16.0 | [email protected] | ProductRelease Notes |
| https://github.com/openfga/openfga/security/advisories/GHSA-8396-jffm-qx4w | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-345 | Insufficient Verification of Data Authenticity | [email protected] |
| CWE-668 | Exposure of Resource to Wrong Sphere | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| openfga helm charts | < 0.3.5 |
CPE
Remediation
| |
| openfga openfga | < 1.16.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 12, 2026 | Initial Analysis | [email protected] |
| Jun 10, 2026 | New CVE Received | [email protected] |