Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Openfga

First CVE: Oct 25, 2022Active for: 4 yearsTotal CVEs: 26
42.1
VTI Score
High

OpenFGA is an open-source authorization-as-a-service platform designed to decouple permission logic from application code, and while its product footprint is narrow, it occupies a critical position in access-control infrastructure across organizations adopting fine-grained permission models. Vulnerabilities affecting the vendor skew strongly toward critical severity, reflecting the elevated stakes of flaws in authorization-enforcement systems where logic errors directly compromise access control. The exposure recurs across the core OpenFGA service and its Helm deployment charts through weakness classes centered on authorization and access-control logic—including improper and incorrect authorization decisions, insufficient verification of data authenticity, and infinite-loop conditions—that highlight the complexity of policy evaluation and state management in a permission engine. Because authorization flaws can cascade silently across dependent applications, defenders should treat OpenFGA disclosures as high-priority regardless of adoption scope and should verify that policy evaluation logic has not drifted from intended configurations. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
26
Total CVEs
More Total CVEs than 97% of tracked vendors
2.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
8.2
Avg CVSS Score
Higher Avg CVSS Score than 80% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Openfga over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 25, 2022
3 years ago
Most Recent CVE
Jul 9, 2026
15 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (26 CVEs).

26 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-33729CRITICAL
OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. In versions prior to 1.13.1, under specific conditi
Mar 27, 20269.836NONO
CVE-2026-34972HIGH
OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. From 1.8.0 to 1.13.1, under specific conditions, Ba
Apr 6, 20268.834NONO
CVE-2026-55689HIGH
OpenFGA is an authorization/permission engine built for developers. Prior to 1.18.0, OpenFGA's OIDC authenticator skipped JWT audience validation when authn.method was set to oidc,
Jul 9, 20268.131NONO
CVE-2025-55213CRITICAL
OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.9.3 to v1.9.4 ( openfga-0.2.40 <= Helm c
Aug 18, 20259.830NONO
CVE-2022-23542CRITICAL
OpenFGA is an authorization/permission engine built for developers and inspired by Google Zanzibar. During an internal security assessment, it was discovered that OpenFGA version 0
Dec 20, 20229.830NONO
CVE-2022-39352CRITICAL
OpenFGA is a high-performance authorization/permission engine inspired by Google Zanzibar. Versions prior to 0.2.5 are vulnerable to authorization bypass under certain conditions.
Nov 8, 20229.830NONO
CVE-2022-39342CRITICAL
OpenFGA is an authorization/permission engine. Versions prior to version 0.2.4 are vulnerable to authorization bypass under certain conditions. Users whose model has a relation def
Oct 25, 20229.830NONO
CVE-2022-39341CRITICAL
OpenFGA is an authorization/permission engine. Versions prior to version 0.2.4 are vulnerable to authorization bypass under certain conditions. Users who have wildcard (`*`) define
Oct 25, 20229.830NONO
CVE-2025-46331CRITICAL
OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.8.10 to v1.3.6 (Helm chart <= openfga-0.
Apr 30, 20259.829NONO
CVE-2026-40293HIGH
OpenFGA is an authorization/permission engine built for developers. In versions 0.1.4 through 1.13.1, when OpenFGA is configured to use preshared-key authentication with the built-
Apr 17, 20267.528NONO
View all 26 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products26 CVEs
27%
31%
42%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network26 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low24 (92.3%)
High2 (7.7%)
Unknown0 (0.0%)
User Interaction
None26 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low9 (34.6%)
High0 (0.0%)
None17 (65.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (26 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Openfga.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Openfga — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Openfga's Products

View all 1 CNAs →

Top CWEs