CVE-2026-55170
CVE-2026-55170 is a medium-severity vulnerability in Openfga Helm Charts with a CVSS 3.x base score of 5.4. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-178.
Key facts
- Severity: Medium (CVSS 3.x base score 5.4)
- CVSS v4: 2.1
- EPSS exploit prediction: 0% (16th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-178
- Affected product: Openfga Helm Charts
- Published:
- Last modified:
Description
OpenFGA is an authorization/permission engine built for developers. Prior to 1.18.0, when MySQL is being used as the datastore and authorization decisions rely on case-sensitive user strings, the tuple, changelog, and authorization_model identifier columns can compare case-distinct values such as user:Alice and user:alice as equivalent, causing two distinct check requests to return the same response. This issue is fixed in 1.18.0.
Frequently asked questions
- What is CVE-2026-55170?
- OpenFGA is an authorization/permission engine built for developers. Prior to 1.18.0, when MySQL is being used as the datastore and authorization decisions rely on case-sensitive user strings, the tuple, changelog, and authorization_model identifier columns can compare case-distinct values such as user:Alice and user:alice as equivalent, causing two distinct check requests to return the same response. This issue is fixed in 1.18.0.
- How severe is CVE-2026-55170?
- CVE-2026-55170 has a CVSS 3.x base score of 5.4, rated medium severity. It is exploitable over network with low attack complexity, requires low privileges and no user interaction. Impact on confidentiality is low, integrity low, and availability none.
- Is CVE-2026-55170 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (16th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-55170?
- CVE-2026-55170 primarily affects Openfga Helm Charts. In total, 2 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2026-55170?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-55170 published?
- CVE-2026-55170 was published on 2026-07-09 and last updated on 2026-07-14.
References
- https://github.com/openfga/helm-charts/commit/96d5517a2693ff5def451dee7d6b9d1baeb281f8
- https://github.com/openfga/helm-charts/releases/tag/openfga-0.3.9
- https://github.com/openfga/openfga/commit/a2e0dbefc3e01a95c785f81a3563bc6571b08b11
- https://github.com/openfga/openfga/releases/tag/v1.18.0
- https://github.com/openfga/openfga/security/advisories/GHSA-cf98-j28v-49v6
Affected products (2)
- cpe:2.3:a:openfga:helm_charts:*:*:*:*:*:openfga:*:*
- cpe:2.3:a:openfga:openfga:*:*:*:*:*:*:*:*
More vulnerabilities in Openfga Helm Charts
- CVE-2025-55213 — Critical (CVSS 9.8): OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google…
- CVE-2025-46331 — Critical (CVSS 9.8): OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google…
- CVE-2025-25196 — Critical (CVSS 9.8): OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google…
- CVE-2024-56323 — Critical (CVSS 9.8): OpenFGA is an authorization/permission engine. IN OpenFGA v1.3.8 to v1.8.2 (Helm chart openfga-0.1.38 to…
- CVE-2026-24851 — High (CVSS 8.8): OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google…
- CVE-2025-64751 — High (CVSS 8.8): OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google…
All CVEs affecting Openfga Helm Charts →
Other CWE-178 vulnerabilities
- CVE-2026-54763 — Critical (CVSS 10.0): Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22, and v3.7.6, Traefik's BasicAuth,…
- CVE-2026-40453 — Critical (CVSS 9.9): The fix for CVE-2025-27636 added setLowerCase(true) to HttpHeaderFilterStrategy so that case-variant header names such…
- CVE-2026-47323 — Critical (CVSS 9.8): Camel-CXF and Camel-Knative Message Header Injection via Missing Inbound Filtering The CXF and Knative…
- CVE-2024-5699 — Critical (CVSS 9.8): In violation of spec, cookie prefixes such as `__Secure` were being ignored if they were not correctly capitalized - by…
- CVE-2023-3545 — Critical (CVSS 9.8): Improper sanitisation in `main/inc/lib/fileUpload.lib.php` in Chamilo LMS <= v1.11.20 on Windows and Apache…
- CVE-2022-29604 — Critical (CVSS 9.8): An issue was discovered in ONOS 2.5.1. An intent with an uppercase letter in a device ID shows the CORRUPT state, which…