CVE-2026-55170EPSS p25.0%
CVE-2026-55170CVE-2026-55170
openfga / helm_charts
Description
OpenFGA is an authorization/permission engine built for developers. Prior to 1.18.0, when MySQL is being used as the datastore and authorization decisions rely on case-sensitive user strings, the tuple, changelog, and authorization_model identifier columns can compare case-distinct values such as user:Alice and user:alice as equivalent, causing two distinct check requests to return the same response. This issue is fixed in 1.18.0.
Scoring
| CVSS | 5.4 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
| EPSS | 0.34% probability of exploitation · percentile 25.0% · 2026-10-05T12:00:23Z |
| Last modified | 2026-07-14 |