OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. From 1.8.0 to 1.13.1, under specific conditions, BatchCheck calls with multiple checks sent for the same object, relation, and user combination can result in improper policy enforcement. This vulnerability is fixed in 1.14.0.
Cite this page
CVE-2026-34972. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2026-34972
Use CWE-863, Openfga vendor hub and Helm Charts product page to widen CVE-2026-34972 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-24851, CVE-2025-64751 and CVE-2025-55213 for nearby disclosures in the same product family.