CVE-2026-33729 affects OpenFGA versions prior to 1.13.1, where a caching vulnerability can lead to incorrect authorization decisions. Specifically, under certain conditions, models using relations with condition evaluation and caching enabled may reuse cached results for different requests due to identical cache keys. This medium-severity vulnerability (CVSS 5.8) has a network attack vector and low attack complexity, requiring low privileges, with a high potential impact on security confidentiality, integrity, and availability. There is currently no evidence of active exploitation, nor is any public exploit code available. Community discussion and media coverage for this vulnerability are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.13.1CPE matchmatch criteria | cpe:2.3:a:openfga:openfga:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.