PT-2026-93748 · Openfga · Openfga

CVE-2026-61709

·

Published

2026-09-16

·

Updated

2026-09-28

CVSS v3.1

5.3

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenFGA versions prior to 1.18.1
Description The ListUsers API could incorrectly return a user who should have been excluded. This occurs when an authorization relation uses an intersection containing a base but not excluded operand, the base is granted through a type-bound public wildcard, and the excluded user also possesses a concrete tuple through another intersection operand. In the expandIntersection() function within pkg/server/commands/listusers/list users rpc.go, the system counted the concrete tuple and wildcard without first rejecting entries in the excludedUsersMap. Consequently, applications using the ListUsers API to enumerate or enforce access might treat an excluded user as authorized.
Recommendations Update to version 1.18.1.

Exploit

Fix

Incorrect Authorization

Improper Preservation of Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-61709
ECHO-CD63-9789-8FD2
GHSA-G3PG-FRFM-PR2M
GO-2026-6488
RHSA-2026:68777
RHSA-2026:71040

Affected Products

Openfga