CVE-2026-55866 | Authzed SpiceDB up to 1.53.x Dispatch Keys computed.go checkRequestToKey/checkRequestToKeyWithCanonical context access control
A vulnerability classified as problematic was found in Authzed SpiceDB up to 1.53.x. Affected by this vulnerability is the function checkRequestToKey/checkRequestToKeyWithCanonical of the file internal/dispatch/keys/computed.go of the component Dispatch Keys. Such manipulation of the argument context leads to improper access controls.
This vulnerability is traded as CVE-2026-55866. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is advised.VulDB Recent EntriesRead More