CVE-2026-55170: OpenFGA MySQL backend: case-insensitive collation on identifier columns causes incorrect authorization decisions

Published Jun 18, 2026
·
Updated

Description

In OpenFGA, when MySQL is being used as the datastore, two distinct check requests can return the same response.

Preconditions

This applies if the following preconditions are met:

1. You run OpenFGA with MySQL as the datastore 2. Your authorization decisions rely on case-sensitive user strings.

Fix Upgrade to OpenFGA 1.18.0 or greater.

Acknowledgements OpenFGA would like to thank @sahajamoth for the detailed report.

Other sources

OpenFGA is an authorization/permission engine built for developers. Prior to 1.18.0, when MySQL is being used as the datastore and authorization decisions rely on case-sensitive user strings, the tuple, changelog, and authorizationmodel identifier columns can compare case-distinct values such as user:Alice and user:alice as equivalent, causing two distinct check requests to return the same response. This issue is fixed in 1.18.0.

MITRE

Affected Software

3 affected componentsFixes available
go/github.com/openfga/openfga<1.18.0
1.18.0
OPenFGA Helm Charts Openfga<0.3.9
OPenFGA OPenFGA<1.18.0

Event History

Jun 18, 2026
Advisory Published
via GitHub·03:05 PM
Data Sourced
via GitHub·03:05 PM
DescriptionWeaknessAffected Software
Jul 9, 2026
CVE Published
via MITRE·09:04 PM
Data Sourced
via MITRE·09:04 PM
DescriptionWeakness
Data Sourced
via NVD·10:17 PM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-55170?

The severity of CVE-2026-55170 is rated as risk level 34.

2

What vulnerability does CVE-2026-55170 address?

CVE-2026-55170 addresses a flaw in OpenFGA where two distinct check requests can return the same response when using MySQL as the datastore.

3

How do I fix CVE-2026-55170?

To fix CVE-2026-55170, ensure that your authorization decisions in OpenFGA are not solely reliant on case-sensitive checks when using MySQL.

4

What systems are affected by CVE-2026-55170?

CVE-2026-55170 affects systems running OpenFGA with MySQL as the datastore.

5

What are the implications of CVE-2026-55170 for my applications?

The implications of CVE-2026-55170 may include incorrect authorization outcomes leading to potential security risks.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203