Threat Advisory

OpenFGA ListUsers Flaw Returns Deliberately-Excluded Users

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Medium
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A medium severity vulnerability affecting github.com/openfga/openfga versions <= 1.18.0, identified as CVE-2026-61709 with a CVSS score of 5.3, exists in OpenFGA that allows a deliberately-excluded user to be returned by the ListUsers API when intersected with another relation granted through a type-bound public wildcard and also granted via a concrete tuple. This flaw occurs if specific preconditions are met, including an intersection relation with an exclusion of the form base but not excluded, where the base side is granted through a type-bound public wildcard, a user excluded by the but not clause is also granted, and the application utilizes ListUsers to enumerate or enforce access. The business impact of this vulnerability is significant as it could lead to incorrect user enumeration or access enforcement, potentially compromising the security and integrity of the system.

RECOMMENDATION:

We recommend you to update github.com/openfga/openfga to version 1.18.1.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A medium severity vulnerability affecting github.com/openfga/openfga versions <= 1.18.0, identified as CVE-2026-61709 with a CVSS score of 5.3, exists in OpenFGA that allows a deliberately-excluded user to be returned by the ListUsers API when intersected with another relation granted through a type-bound public wildcard and also granted via a concrete tuple. This flaw occurs if specific preconditions are met, including an intersection relation with an exclusion of the form base but not excluded, where the base side is granted through a type-bound public wildcard, a user excluded by the but not clause is also granted, and the application utilizes ListUsers to enumerate or enforce access. The business impact of this vulnerability is significant as it could lead to incorrect user enumeration or access enforcement, potentially compromising the security and integrity of the system.

RECOMMENDATION:

We recommend you to update github.com/openfga/openfga to version 1.18.1.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu