Improper Policy Enforcement in OpenFGA Authorization Engine by OpenFGA
CVE-2026-24851
5.8MEDIUM
What is CVE-2026-24851?
OpenFGA, a flexible authorization engine, suffers from a vulnerability that affects its ability to enforce policies correctly during certain Check calls. Specifically, the flaw arises when a model includes relations directly assignable by both public and non-public access. This could lead to unauthorized access based on improper relation assignments. The issue has been addressed in version 1.11.3, making it imperative for users to update to this version or later to ensure security.
Affected Version(s)
openfga < 1.11.3
