CVE-2026-55689

MEDIUM

OpenFGA: OIDC audience validation skipped when --authn-oidc-audience is unset

Title source: cna
STIX 2.1

Description

OpenFGA is an authorization/permission engine built for developers. Prior to 1.18.0, OpenFGA's OIDC authenticator skipped JWT audience validation when authn.method was set to oidc, authn.oidc.issuer was configured, and authn.oidc.audience was not set, allowing a token minted for an unrelated service by the same identity provider to authenticate to OpenFGA. This issue is fixed in 1.18.0.

Scores

CVSS v3 6.8
EPSS 0.0030
EPSS Percentile 22.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-287
Status published
Products (3)
openfga/helm_charts < 0.3.9
openfga/openfga < 1.18.0 (2 CPE variants)
openfga/openfga 0 - 1.18.0Go
Published Jul 09, 2026
Tracked Since Jul 10, 2026