Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-55170

25
FAUCET Score

OpenFGA is an authorization/permission engine built for developers. Prior to 1.18.0, when MySQL is being used as the datastore and authorization decisions rely on case-sensitive user strings, the tuple, changelog, and authorization_model identifier columns can compare case-distinct values such as user:Alice and user:alice as equivalent, causing two distinct check requests to return the same response. This issue is fixed in 1.18.0.

First published: Jul 9, 2026Last modified: Jul 9, 2026

Impacted Technologies

VendorProductVersion(s)CPE
< 0.3.9CPE matchmatch criteria
cpe:2.3:a:openfga:helm_charts:*:*:*:*:*:openfga:*:*
< 1.18.0CPE matchmatch criteria
cpe:2.3:a:openfga:openfga:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

2.1LOW

CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
PRESENT
Privileges Required
LOW
User Interaction
PASSIVE
VS Confidentiality
LOW
VS Integrity
LOW
VS Availability
NONE
SS Confidentiality
LOW
SS Integrity
LOW
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.25%
Probability of exploitation in next 30 days
EPSS Percentile
16.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0025 is in the 19th percentile among its peer group of 21,974 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
gopatch availablevia ghsa
Product: github.com/openfga/openfgaFixed in: 1.18.0

Vendor Advisories (1)

goGHSA-cf98-j28v-49v6low

OpenFGA Improper Policy Enforcement

Jun 18, 2026

References

github.com / openfga/helm-charts/commit/96d5517a2693ff5def451dee7d6b9d1baeb281f8
Patch
github.com / openfga/helm-charts/releases/tag/openfga-0.3.9
ProductRelease Notes
github.com / openfga/openfga/commit/a2e0dbefc3e01a95c785f81a3563bc6571b08b11
Patch
github.com / openfga/openfga/releases/tag/v1.18.0
ProductRelease Notes
github.com / openfga/openfga/security/advisories/GHSA-cf98-j28v-49v6
Vendor Advisory