CVE-2026-55170
OpenFGA Improper Policy Enforcement
Summary
## Description In OpenFGA, when MySQL is being used as the datastore, two distinct check requests can return the same response. ## Preconditions This applies if the following preconditions are met: 1. You run OpenFGA with MySQL as the datastore 2. Your authorization decisions rely on case-sensitive user strings. ## Fix Upgrade to OpenFGA 1.18.0 or greater. ## Acknowledgements OpenFGA would like to thank @sahajamoth for the detailed report.
Affected packages
| Ecosystem | Package | Affected versions | Fixed versions |
|---|---|---|---|
| Go | github.com/openfga/openfga | — | 1.18.0 |
Remediation: Upgrade to 1.18.0 or later.
References
Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.
CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.
EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.