Authorization Bypass Vulnerability in OpenFGA by OpenFGA
CVE-2025-25196

5.8MEDIUM

Key Information:

Vendor

Openfga

Status
Vendor
CVE Published:
19 February 2025

What is CVE-2025-25196?

OpenFGA, a leading authorization and permission engine inspired by Google Zanzibar, suffers from an authorization bypass vulnerability in versions prior to v1.8.5. The vulnerability occurs when the Check API or ListObjects method is called using specific relational models that permit both public access and usersets of the same type. This scenario allows unauthorized users to gain access under specific conditions, potentially exposing sensitive data. Users are strongly recommended to upgrade to version v1.8.5, which ensures backward compatibility, as no effective workarounds exist.

Affected Version(s)

openfga < 1.8.5

References

CVSS V4

Score:
5.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.