PatchSiren cyber security CVE debrief
CVE-2026-55689 openfga CVE debrief
CVE-2026-55689 is a MEDIUM severity vulnerability in OpenFGA's OIDC authenticator. Prior to version 1.18.0, the OIDC authenticator skipped JWT audience validation when certain conditions were met, potentially allowing unauthorized access. This issue is fixed in version 1.18.0. Users of OpenFGA prior to version 1.18.0 who utilize OIDC authentication should verify their configurations and update to the latest version to mitigate potential unauthorized access. The vulnerability allows a token intended for a different service by the same identity provider to be used for authentication.
- Vendor
- openfga
- Product
- Unknown
- CVSS
- MEDIUM 6.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-09
- Original CVE updated
- 2026-07-14
- Advisory published
- 2026-07-09
- Advisory updated
- 2026-07-14
Who should care
Users of OpenFGA prior to version 1.18.0 who utilize OIDC authentication should verify their configurations and update to the latest version to mitigate potential unauthorized access. This includes OpenFGA operators, platform administrators, vulnerability management teams, and security teams who need to assess the impact of the vulnerability and take necessary actions.
Technical summary
OpenFGA's OIDC authenticator had a vulnerability where JWT audience validation was skipped under specific configuration conditions. This could allow a token intended for a different service by the same identity provider to be used for authentication. The issue was addressed in OpenFGA version 1.18.0 by implementing proper audience validation. The vulnerability affects OpenFGA versions prior to 1.18.0 and is related to OIDC authentication configurations.
Defensive priority
Medium priority for users of OpenFGA with OIDC authentication; immediate review and update recommended.
Recommended defensive actions
- Review OpenFGA configurations for OIDC authentication and ensure proper audience validation.
- Update OpenFGA to version 1.18.0 or later.
- Verify identity provider configurations for proper JWT audience settings.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The CVE record and NVD details were used to assess the vulnerability. Limited additional information was available, so further verification is recommended. OpenFGA's OIDC authenticator vulnerability allows unauthorized access under specific configurations. Users should verify their configurations and update to the latest version. The CVE record was published on 2026-07-09T22:17:06.553Z and has not been modified since then. No additional details are provided in the source corpus.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-55689 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-55689
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-55689 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-55689
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/openfga/helm-ch
-
Source reference
Unverified legacy reference
URL: https://github.com/openfga/helm-charts/releases/tag/openfga-0.3.9
-
Source reference
Unverified legacy reference
URL: https://github.com/openfga/openfga/commit/44596773b2e62738720ef215bf7fa04352954271
-
Source reference
Unverified legacy reference
URL: https://github.com/openfga/openfga/releases/tag/v1.18.0
-
Source reference
Unverified legacy reference
URL: https://github.com/openfga/openfga/security/advisories/GHSA-hcxc-wf8j-23hv
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.