THREAT OPS › Threat News › [NVD] CVE-2026-40293 (MEDIUM 6.5) — OpenFGA is an authorization/permission engine built for developers. In versions 0.1.4 through 1.13.1, when OpenFGA is configured to use preshared-key authentication with the built-in playground enabled, the local server includes the preshared API key in the HTML response of the /
[NVD] CVE-2026-40293 (MEDIUM 6.5) — OpenFGA is an authorization/permission engine built for developers. In versions 0.1.4 through 1.13.1, when OpenFGA is configured to use preshared-key authentication with the built-in playground enabled, the local server includes the preshared API key in the HTML response of the /
CVE-2026-40293 CVSS: 6.5 MEDIUM Published: 2026-04-17T21:16:34.567
OpenFGA is an authorization/permission engine built for developers. In versions 0.1.4 through 1.13.1, when OpenFGA is configured to use preshared-key authentication with the built-in playground enabled, the local server includes the preshared API key in the HTML response of the /playground endpoint. The /playground endpoint is ena
Indicators of compromise
- CVE-2026-40293cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-40293