Vulnerability record · CVE-2026-55689 · published 9 July 2026
CVE-2026-55689: Openfga helm charts improper authentication vulnerability
Openfga · Helm Charts
OpenFGA is an authorization/permission engine built for developers. Prior to 1.18.0, OpenFGA's OIDC authenticator skipped JWT audience validation when authn.method was set to oidc, authn.oidc.issuer was configured, and authn.oidc.audience was not set, allowing a token minted for an unrelated service by the same identity provider to authenticate to OpenFGA. This issue is fixed in 1.18.0.
Description
OpenFGA is an authorization/permission engine built for developers. Prior to 1.18.0, OpenFGA's OIDC authenticator skipped JWT audience validation when authn.method was set to oidc, authn.oidc.issuer was configured, and authn.oidc.audience was not set, allowing a token minted for an unrelated service by the same identity provider to authenticate to OpenFGA. This issue is fixed in 1.18.0.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/openfga/helm-ch | Broken Link |
| https://github.com/openfga/helm-charts/releases/tag/openfga-0.3.9 | ProductRelease Notes |
| https://github.com/openfga/openfga/commit/44596773b2e62738720ef215bf7fa04352954271 | Patch |
| https://github.com/openfga/openfga/releases/tag/v1.18.0 | ProductRelease Notes |
| https://github.com/openfga/openfga/security/advisories/GHSA-hcxc-wf8j-23hv | Vendor Advisory |
Track CVE-2026-55689 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-55689), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.