Description
SpiceDB is an open source database system for creating and managing security-critical application permissions. From 1.34.0 until 1.54.0, SpiceDB can return PERMISSIONSHIP_HAS_PERMISSION instead of PERMISSIONSHIP_CONDITIONAL_PERMISSION or PERMISSIONSHIP_NO_PERMISSION because checkRequestToKey() and checkRequestToKeyWithCanonical() in internal/dispatch/keys/computed.go omit CheckHints when constructing dispatch Check cache keys. The incorrect result requires a permission combining relations with intersection or exclusion, a subject reachable through caveated and non-caveated branches, LookupResources with a context parameter running concurrently with CheckPermission or CheckBulkPermissions for the same resource and subject, and an enabled dispatch result cache. Under these conditions, a result computed for one hint set can poison the cache entry used by a semantically different authorization check, allowing permission without satisfying the caveat. This issue is fixed in version 1.54.0.
Published: 2026-09-14
Score: 3.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: Unconditional Permission Grant
Action: Apply Patch
AI Analysis

Impact

SpiceDB is an open source database for managing application permissions. From versions 1.34.0 to 1.53.x, the system can return a permanently granted permission (PERMISSIONSHIP_HAS_PERMISSION) instead of the intended conditional or denied state because the functions checkRequestToKey() and checkRequestToKeyWithCanonical() omit CheckHints when forming dispatch cache keys. Under the conditions of intersecting or excluding relations, a subject that traverses both caveated and non‑caveated branches, and when LookupResources with a context parameter runs concurrently with CheckPermission or CheckBulkPermissions for the same resource and subject, a cache entry computed for one hint set can be reused for a semantically different check. This allows a user to obtain permission without satisfying the required caveat. The issue is fixed in version 1.54.0.

Affected Systems

authzed's SpiceDB versions 1.34.0 through 1.53.x are affected. Any deployment that uses the internal dispatch cache, performs permission checks that involve intersecting or excluding relations, a subject reachable through both caveated and non‑caveated branches, and concurrently runs LookupResources with a context parameter during CheckPermission or CheckBulkPermissions for the same resource and subject, will be vulnerable. The fix was introduced in release 1.54.0; upgrading to that version or later eliminates the issue.

Risk and Exploitability

The CVSS score of 3.7 indicates low severity, and EPSS score is < 1%, indicating a low likelihood of exploitation. Exploitation requires a specific combination of concurrent permission checks, an enabled dispatch result cache, and a permission graph that contains both caveated and non‑caveated branches. While an attacker with knowledge of the permission structure could trigger the cache poisoning, widespread attacks would likely be constrained by these requirements.

Generated by OpenCVE AI on September 20, 2026 at 23:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to authzed/spicedb version 1.54.0 or later, which fixes the cache key construction bug.
  • If an upgrade cannot be performed immediately, disable or clear the dispatch result cache for permission checks that involve caveats to avoid cache poisoning.
  • Review application architecture to ensure that permission checks do not rely on concurrent lookups with overlapping resource and subject combinations when using cached results.

Generated by OpenCVE AI on September 20, 2026 at 23:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-4vrg-r928-h5vv SpiceDB: Checks involving relations with caveats can result in unconditional permission when conditional permission is expected
History

Tue, 15 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
First Time appeared Authzed
Authzed spicedb
Vendors & Products Authzed
Authzed spicedb

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description SpiceDB is an open source database system for creating and managing security-critical application permissions. From 1.34.0 until 1.54.0, SpiceDB can return PERMISSIONSHIP_HAS_PERMISSION instead of PERMISSIONSHIP_CONDITIONAL_PERMISSION or PERMISSIONSHIP_NO_PERMISSION because checkRequestToKey() and checkRequestToKeyWithCanonical() in internal/dispatch/keys/computed.go omit CheckHints when constructing dispatch Check cache keys. The incorrect result requires a permission combining relations with intersection or exclusion, a subject reachable through caveated and non-caveated branches, LookupResources with a context parameter running concurrently with CheckPermission or CheckBulkPermissions for the same resource and subject, and an enabled dispatch result cache. Under these conditions, a result computed for one hint set can poison the cache entry used by a semantically different authorization check, allowing permission without satisfying the caveat. This issue is fixed in version 1.54.0.
Title SpiceDBChecks involving relations with caveats can result in unconditional permission when conditional permission is expected
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T18:15:41.075Z

Reserved: 2026-06-17T16:44:40.996Z

Link: CVE-2026-55866

cve-icon Vulnrichment

Updated: 2026-09-14T18:15:36.347Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T18:17:56.150

Modified: 2026-09-30T19:38:27.293

Link: CVE-2026-55866

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T23:15:04Z

Weaknesses