QSearchQSearch

CVE-2026-48096

5.0 MEDIUM

OpenFGA is an authorization/permission engine built for developers

Published: 2026-06-10 · Last updated: 2026-06-10

Severity and scoring

CVSS
5.0 MEDIUM
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
CWE
CWE-345, CWE-668

Description

OpenFGA is an authorization/permission engine built for developers. Prior to version 1.16.0, when iterator caching is enabled, two distinct check requests can produce the same cache key, leading to OpenFGA reusing an earlier cached result for a subsequent request. This issue has been patched in version 1.16.0.

Source: NVD

References

Related CVEs

Same CWE

  • CVE-2026-46654 Plonky3 is a toolkit for polynomial IOPs (PIOPs)
  • CVE-2026-46539 Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm (5.9 MEDIUM)
  • CVE-2026-42535 A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV proper... (9.1 CRITICAL)
  • CVE-2026-7792 The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Insuf... (5.3 MEDIUM)
  • CVE-2026-8608 The Event Monster – Event Management, Events Calendar, Tickets plugin for WordPress is vulnerable to Insufficient Verification of Data Au... (5.3 MEDIUM)