CVE-2026-46668

Severity CVSS v4.0:
LOW
Type:
CWE-285 Improper Authorization
Publication date:
10/06/2026
Last modified:
11/06/2026

Description

SpiceDB is an open source database system for creating and managing security-critical application permissions. From version 1.15.0 to before version 1.52.0, caveat structures with nested lists can result in improper cache reuse. This issue has been patched in version 1.52.0.