{"schema_version":1,"title":"Authzed vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 5 vulnerabilities in Authzed: 0 in the last 7 days and 1 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-55866, was published on 14 September 2026. 1 technology has a page of its own.","url":"https://junglewise.ai/threats/vendors/authzed","json_url":"https://junglewise.ai/threats/vendors/authzed.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/authzed","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":0,"all_time":5,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":1,"last_90_days":1,"last_365_days":5},"latest":[{"cve":"CVE-2026-55866","cvss":3.7,"epss":0.0034,"slug":"cve-2026-55866-authzed-spicedb-incorrect-authorization-in-caveated-relations","title":"SpiceDB is an open source database system for creating and managing security-critical application permissions. From 1.34.0 until 1.54.0, Spi","severity":"low","exploited":false,"published_at":"2026-09-14T18:17:56.15+00:00","url":"https://junglewise.ai/threats/cve-2026-55866-authzed-spicedb-incorrect-authorization-in-caveated-relations"},{"cve":"CVE-2026-46668","cvss":4,"epss":0.0035,"slug":"cve-2026-46668-authzed-spicedb-improper-authorization-via-cache-collision-in","title":"Authzed SpiceDB improper authorization via cache collision in caveats","severity":"medium","exploited":false,"published_at":"2026-06-10T22:16:59.893+00:00","url":"https://junglewise.ai/threats/cve-2026-46668-authzed-spicedb-improper-authorization-via-cache-collision-in"},{"cve":"CVE-2026-40091","cvss":6,"epss":0.0018,"slug":"cve-2026-40091-authzed-spicedb-sensitive-information-leak-in-startup-logs","title":"Authzed SpiceDB sensitive information leak in startup logs","severity":"medium","exploited":false,"published_at":"2026-04-14T22:33:06+00:00","url":"https://junglewise.ai/threats/cve-2026-40091-authzed-spicedb-sensitive-information-leak-in-startup-logs"},{"cve":"CVE-2025-65111","cvss":4,"epss":0.0022,"slug":"cve-2025-65111-authzed-spicedb-incomplete-lookupresources-results-in-complex","title":"Authzed SpiceDB incomplete LookupResources results in complex schemas","severity":"medium","exploited":false,"published_at":"2025-11-21T18:06:00+00:00","url":"https://junglewise.ai/threats/cve-2025-65111-authzed-spicedb-incomplete-lookupresources-results-in-complex"},{"cve":"CVE-2025-64529","cvss":6.5,"epss":0.0025,"slug":"cve-2025-64529-authzed-spicedb-silent-failure-in-writerelationships","title":"Authzed SpiceDB silent failure in WriteRelationships","severity":"medium","exploited":false,"published_at":"2025-11-13T22:58:20+00:00","url":"https://junglewise.ai/threats/cve-2025-64529-authzed-spicedb-silent-failure-in-writerelationships"}],"vendor":{"hub":true,"name":"Authzed","slug":"authzed","homepage":"https://authzed.com/","description":"Authzed is a software company specializing in relationship-based access control and permissions management systems.","url":"https://junglewise.ai/threats/vendors/authzed"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cve":"CVE-2025-64529","cvss":6.5,"epss":0.0025,"slug":"cve-2025-64529-authzed-spicedb-silent-failure-in-writerelationships","title":"Authzed SpiceDB silent failure in WriteRelationships","severity":"medium","exploited":false,"published_at":"2025-11-13T22:58:20+00:00","url":"https://junglewise.ai/threats/cve-2025-64529-authzed-spicedb-silent-failure-in-writerelationships"},{"cve":"CVE-2026-40091","cvss":6,"epss":0.0018,"slug":"cve-2026-40091-authzed-spicedb-sensitive-information-leak-in-startup-logs","title":"Authzed SpiceDB sensitive information leak in startup logs","severity":"medium","exploited":false,"published_at":"2026-04-14T22:33:06+00:00","url":"https://junglewise.ai/threats/cve-2026-40091-authzed-spicedb-sensitive-information-leak-in-startup-logs"},{"cve":"CVE-2026-46668","cvss":4,"epss":0.0035,"slug":"cve-2026-46668-authzed-spicedb-improper-authorization-via-cache-collision-in","title":"Authzed SpiceDB improper authorization via cache collision in caveats","severity":"medium","exploited":false,"published_at":"2026-06-10T22:16:59.893+00:00","url":"https://junglewise.ai/threats/cve-2026-46668-authzed-spicedb-improper-authorization-via-cache-collision-in"},{"cve":"CVE-2025-65111","cvss":4,"epss":0.0022,"slug":"cve-2025-65111-authzed-spicedb-incomplete-lookupresources-results-in-complex","title":"Authzed SpiceDB incomplete LookupResources results in complex schemas","severity":"medium","exploited":false,"published_at":"2025-11-21T18:06:00+00:00","url":"https://junglewise.ai/threats/cve-2025-65111-authzed-spicedb-incomplete-lookupresources-results-in-complex"},{"cve":"CVE-2026-55866","cvss":3.7,"epss":0.0034,"slug":"cve-2026-55866-authzed-spicedb-incorrect-authorization-in-caveated-relations","title":"SpiceDB is an open source database system for creating and managing security-critical application permissions. From 1.34.0 until 1.54.0, Spi","severity":"low","exploited":false,"published_at":"2026-09-14T18:17:56.15+00:00","url":"https://junglewise.ai/threats/cve-2026-55866-authzed-spicedb-incorrect-authorization-in-caveated-relations"}],"generated_at":"2026-09-26T15:07:00.181821+00:00","technologies":[{"name":"Authzed SpiceDB","slug":"spicedb","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/spicedb"}]}