OpenFGA is an authorization/permission engine built for developers and inspired by Google Zanzibar. During an internal security assessment, it was discovered that OpenFGA version 0.3.0 is vulnerable to authorization bypass under certain conditions. This issue has been patched in version 0.3.1 and is backward compatible.
Cite this page
CVE-2022-23542. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2022-23542
Use CWE-285, Openfga vendor hub and Openfga product page to widen CVE-2022-23542 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2024-42473, CVE-2026-40293 and CVE-2026-33729 for nearby disclosures in the same product family.