PT-2026-93748 · Openfga · Openfga
CVE-2026-61709
·
Published
2026-09-16
·
Updated
2026-09-28
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OpenFGA versions prior to 1.18.1
Description
The ListUsers API could incorrectly return a user who should have been excluded. This occurs when an authorization relation uses an intersection containing a base but not excluded operand, the base is granted through a type-bound public wildcard, and the excluded user also possesses a concrete tuple through another intersection operand. In the
expandIntersection() function within pkg/server/commands/listusers/list users rpc.go, the system counted the concrete tuple and wildcard without first rejecting entries in the excludedUsersMap. Consequently, applications using the ListUsers API to enumerate or enforce access might treat an excluded user as authorized.Recommendations
Update to version 1.18.1.
Exploit
Fix
Incorrect Authorization
Improper Preservation of Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openfga