CVE-2026-55689: Openfga Helm Charts

High severity, CVSS 8.1. EPSS: 0.4% chance of exploitation in the next 30 days.

OpenFGA is an authorization/permission engine built for developers. Prior to 1.18.0, OpenFGA's OIDC authenticator skipped JWT audience validation when authn.method was set to oidc, authn.oidc.issuer was configured, and authn.oidc.audience was not set, allowing a token minted for an unrelated service by the same identity provider to authenticate to OpenFGA. This issue is fixed in 1.18.0.

Affected products

  • Openfga Helm Charts: before 0.3.9 (fixed in 0.3.9)
  • Openfga Openfga: before 1.18.0 (fixed in 1.18.0)

Published 2026-07-09. Last modified 2026-07-14.