Authorization and Permission Engine Vulnerability in OpenFGA by OpenFGA
CVE-2026-61709

5.3MEDIUM

Key Information:

Vendor

Openfga

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-61709?

OpenFGA, an authorization and permission engine, had a vulnerability where its ListUsers API could incorrectly authorize users. Specifically, prior to version 1.18.1, the API could return excluded users if certain conditions involving authorization relations and wildcard types were met. This flaw arose from an oversight in how intersecting user relations were counted, allowing unauthorized users to potentially access sensitive data. Developers using the ListUsers API for access control were at risk of treating these excluded users as authorized. The issue is addressed in version 1.18.1.

Affected Version(s)

openfga < 1.18.1

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.