CVE-2026-55866: CWE-863: Incorrect Authorization in authzed spicedb
SpiceDB is an open source database system for creating and managing security-critical application permissions. From 1.34.0 until 1.54.0, SpiceDB can return PERMISSIONSHIP_HAS_PERMISSION instead of PERMISSIONSHIP_CONDITIONAL_PERMISSION or PERMISSIONSHIP_NO_PERMISSION because checkRequestToKey() and checkRequestToKeyWithCanonical() in internal/dispatch/keys/computed.go omit CheckHints when constructing dispatch Check cache keys. The incorrect result requires a permission combining relations with intersection or exclusion, a subject reachable through caveated and non-caveated branches, LookupResources with a context parameter running concurrently with CheckPermission or CheckBulkPermissions for the same resource and subject, and an enabled dispatch result cache. Under these conditions, a result computed for one hint set can poison the cache entry used by a semantically different authorization check, allowing permission without satisfying the caveat. This issue is fixed in version 1.54.0.
AI Analysis
Technical Summary
SpiceDB, an open source database for managing application permissions, contains an incorrect authorization vulnerability (CWE-863) in versions >=1.34.1 and <1.54.0. The functions checkRequestToKey() and checkRequestToKeyWithCanonical() omit CheckHints when building dispatch cache keys, causing the dispatch result cache to be poisoned. Under conditions involving permission combinations with intersection or exclusion, subjects reachable via caveated and non-caveated branches, concurrent LookupResources and CheckPermission calls for the same resource and subject, and an enabled dispatch cache, a cached result computed for one hint set can be reused incorrectly for a semantically different authorization check. This leads to permission being granted without satisfying the caveat. The flaw is resolved in version 1.54.0.
Potential Impact
The vulnerability can cause incorrect authorization decisions, allowing permissions to be granted without fulfilling required caveats. This impacts the integrity of permission enforcement but does not affect confidentiality or availability. The CVSS v3.1 base score is 3.7 (low severity), reflecting a network attack vector with high attack complexity and no privileges or user interaction required. There are no known exploits in the wild.
Mitigation Recommendations
Upgrade SpiceDB to version 1.54.0 or later, where this issue is fixed. No other mitigations are indicated. Patch status is confirmed by the vendor advisory stating the fix is in 1.54.0.
CVE-2026-55866: CWE-863: Incorrect Authorization in authzed spicedb
Description
SpiceDB is an open source database system for creating and managing security-critical application permissions. From 1.34.0 until 1.54.0, SpiceDB can return PERMISSIONSHIP_HAS_PERMISSION instead of PERMISSIONSHIP_CONDITIONAL_PERMISSION or PERMISSIONSHIP_NO_PERMISSION because checkRequestToKey() and checkRequestToKeyWithCanonical() in internal/dispatch/keys/computed.go omit CheckHints when constructing dispatch Check cache keys. The incorrect result requires a permission combining relations with intersection or exclusion, a subject reachable through caveated and non-caveated branches, LookupResources with a context parameter running concurrently with CheckPermission or CheckBulkPermissions for the same resource and subject, and an enabled dispatch result cache. Under these conditions, a result computed for one hint set can poison the cache entry used by a semantically different authorization check, allowing permission without satisfying the caveat. This issue is fixed in version 1.54.0.
CVSS v3.1
Score 3.7low
Affected software
authzed
spicedb
pkg:github/authzed/spicedbRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
SpiceDB, an open source database for managing application permissions, contains an incorrect authorization vulnerability (CWE-863) in versions >=1.34.1 and <1.54.0. The functions checkRequestToKey() and checkRequestToKeyWithCanonical() omit CheckHints when building dispatch cache keys, causing the dispatch result cache to be poisoned. Under conditions involving permission combinations with intersection or exclusion, subjects reachable via caveated and non-caveated branches, concurrent LookupResources and CheckPermission calls for the same resource and subject, and an enabled dispatch cache, a cached result computed for one hint set can be reused incorrectly for a semantically different authorization check. This leads to permission being granted without satisfying the caveat. The flaw is resolved in version 1.54.0.
Potential Impact
The vulnerability can cause incorrect authorization decisions, allowing permissions to be granted without fulfilling required caveats. This impacts the integrity of permission enforcement but does not affect confidentiality or availability. The CVSS v3.1 base score is 3.7 (low severity), reflecting a network attack vector with high attack complexity and no privileges or user interaction required. There are no known exploits in the wild.
Mitigation Recommendations
Upgrade SpiceDB to version 1.54.0 or later, where this issue is fixed. No other mitigations are indicated. Patch status is confirmed by the vendor advisory stating the fix is in 1.54.0.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-06-17T16:44:40.996Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6aa8300055bf5e2cf5600a61
Added to database: 09/14/2026, 17:33:52 UTC
Last enriched: 09/14/2026, 17:47:19 UTC
Last updated: 09/15/2026, 05:11:16 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.