CVE-2026-34972
ADVISORY - githubSummary
Description
In OpenFGA, under specific conditions, BatchCheck calls with multiple checks sent for the same object, relation, and user combination can result in improper policy enforcement.
Am I affected?
You are affected if you meet the following preconditions:
- You execute BatchCheck operations which rely on context.
- Multiple checks are sent within a single BatchCheck operation for the same user/object/relation combination, each containing context.
- The contexts between those checks differ in a specific way
Fix
Upgrade to OpenFGA v1.14.0
Acknowledgement
OpenFGA would like to thank @bugbunny-research for the discovery and detailed report.
Common Weakness Enumeration (CWE)
Incorrect Authorization
Incorrect Authorization
Authorization Bypass Through User-Controlled Key
Docker
CVE-2026-34972
-
NIST
1.6
CVSS SCORE
5mediumGitHub
1.6
CVSS SCORE
5mediumRed Hat
1.6
CVSS SCORE
4.2mediumChainguard
CGA-rfvj-mw43-h8w8
-
minimos
MINI-2q75-9w6m-gvjw
-
minimos
MINI-668m-4jv8-q77w
-
minimos
MINI-7rj9-c6j7-hhv5
-
minimos
MINI-7xw6-9v6v-v7c5
-
minimos
MINI-8786-9qqj-wp4h
-
minimos
MINI-8f64-j27p-r8c5
-
minimos
MINI-c3rw-pmh3-wx28
-
minimos
MINI-cpcf-xxrx-rw2q
-
minimos
MINI-f8jv-3925-x4jx
-
minimos
MINI-jmwj-j37g-chjp
-
minimos
MINI-m4xg-7jmp-54q9
-
minimos
MINI-mg7j-mpxm-wwr8
-
minimos
MINI-mhc9-633j-wq4j
-
minimos
MINI-pjm8-x99f-q9f2
-
minimos
MINI-r3pr-gfxq-m2m3
-
minimos
MINI-vfw9-4wfh-rhq9
-
minimos
MINI-x7x8-4gx6-gpfm
-
minimos
MINI-xhgj-fxvp-2x27
-