THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-40293 (MEDIUM 6.5) — OpenFGA is an authorization/permission engine built for developers. In versions 0.1.4 through 1.13.1, when OpenFGA is configured to use preshared-key authentication with the built-in playground enabled, the local server includes the preshared API key in the HTML response of the /

[NVD] CVE-2026-40293 (MEDIUM 6.5) — OpenFGA is an authorization/permission engine built for developers. In versions 0.1.4 through 1.13.1, when OpenFGA is configured to use preshared-key authentication with the built-in playground enabled, the local server includes the preshared API key in the HTML response of the /

lownvdPublished 2026-04-17

CVE-2026-40293 CVSS: 6.5 MEDIUM Published: 2026-04-17T21:16:34.567

OpenFGA is an authorization/permission engine built for developers. In versions 0.1.4 through 1.13.1, when OpenFGA is configured to use preshared-key authentication with the built-in playground enabled, the local server includes the preshared API key in the HTML response of the /playground endpoint. The /playground endpoint is ena

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-40293