Authorization and Permission Engine Vulnerability in OpenFGA by OpenFGA
CVE-2026-61709
5.3MEDIUM
What is CVE-2026-61709?
OpenFGA, an authorization and permission engine, had a vulnerability where its ListUsers API could incorrectly authorize users. Specifically, prior to version 1.18.1, the API could return excluded users if certain conditions involving authorization relations and wildcard types were met. This flaw arose from an oversight in how intersecting user relations were counted, allowing unauthorized users to potentially access sensitive data. Developers using the ListUsers API for access control were at risk of treating these excluded users as authorized. The issue is addressed in version 1.18.1.
Affected Version(s)
openfga < 1.18.1
