OpenFGA is an open-source authorization-as-a-service platform designed to decouple permission logic from application code, and while its product footprint is narrow, it occupies a critical position in access-control infrastructure across organizations adopting fine-grained permission models. Vulnerabilities affecting the vendor skew strongly toward critical severity, reflecting the elevated stakes of flaws in authorization-enforcement systems where logic errors directly compromise access control. The exposure recurs across the core OpenFGA service and its Helm deployment charts through weakness classes centered on authorization and access-control logic—including improper and incorrect authorization decisions, insufficient verification of data authenticity, and infinite-loop conditions—that highlight the complexity of policy evaluation and state management in a permission engine. Because authorization flaws can cascade silently across dependent applications, defenders should treat OpenFGA disclosures as high-priority regardless of adoption scope and should verify that policy evaluation logic has not drifted from intended configurations. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openfga over time
Signals from CVEs in this vendor scope (26 CVEs).
26 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-33729CRITICAL OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. In versions prior to 1.13.1, under specific conditi | Mar 27, 2026 | 9.8 | 36 | NO | NO |
CVE-2026-34972HIGH OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. From 1.8.0 to 1.13.1, under specific conditions, Ba | Apr 6, 2026 | 8.8 | 34 | NO | NO |
CVE-2026-55689HIGH OpenFGA is an authorization/permission engine built for developers. Prior to 1.18.0, OpenFGA's OIDC authenticator skipped JWT audience validation when authn.method was set to oidc, | Jul 9, 2026 | 8.1 | 31 | NO | NO |
CVE-2025-55213CRITICAL OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.9.3 to v1.9.4 ( openfga-0.2.40 <= Helm c | Aug 18, 2025 | 9.8 | 30 | NO | NO |
CVE-2022-23542CRITICAL OpenFGA is an authorization/permission engine built for developers and inspired by Google Zanzibar. During an internal security assessment, it was discovered that OpenFGA version 0 | Dec 20, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-39352CRITICAL OpenFGA is a high-performance authorization/permission engine inspired by Google Zanzibar. Versions prior to 0.2.5 are vulnerable to authorization bypass under certain conditions. | Nov 8, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-39342CRITICAL OpenFGA is an authorization/permission engine. Versions prior to version 0.2.4 are vulnerable to authorization bypass under certain conditions. Users whose model has a relation def | Oct 25, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-39341CRITICAL OpenFGA is an authorization/permission engine. Versions prior to version 0.2.4 are vulnerable to authorization bypass under certain conditions. Users who have wildcard (`*`) define | Oct 25, 2022 | 9.8 | 30 | NO | NO |
CVE-2025-46331CRITICAL OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.8.10 to v1.3.6 (Helm chart <= openfga-0. | Apr 30, 2025 | 9.8 | 29 | NO | NO |
CVE-2026-40293HIGH OpenFGA is an authorization/permission engine built for developers. In versions 0.1.4 through 1.13.1, when OpenFGA is configured to use preshared-key authentication with the built- | Apr 17, 2026 | 7.5 | 28 | NO | NO |
Signals from CVEs in this vendor scope (26 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openfga.
Media articles that mention a CVE ID that affects a product developed by Openfga — matched by CVE ID, not by vendor name.