CVE-2026-61709
MEDIUMDescription
OpenFGA is an authorization and permission engine built for developers. Prior to 1.18.1, the ListUsers API could return a user that should have been excluded when an authorization relation used an intersection containing a base but not excluded operand, the base was granted through a type-bound public wildcard, and the excluded user also had a concrete tuple through another intersection operand. In pkg/server/commands/listusers/list_users_rpc.go, expandIntersection counted the concrete tuple and wildcard without first rejecting entries in excludedUsersMap. Applications that used ListUsers to enumerate or enforce access could therefore treat an excluded user as authorized. This issue is fixed in version 1.18.1.
Is your site exposed to CVE-2026-61709?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
References
Frequently Asked Questions
What is CVE-2026-61709? +
How severe is CVE-2026-61709? +
How do I check if I'm vulnerable to CVE-2026-61709? +
Related Vulnerabilities
Permissions bypass in M-Files Connector for Copilot before version 24.9.3 allows authenticated user to access limited amount of documents via …
SystemUI has an incorrect component protection setting, which allows access to specific information.
In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content …
Any unauthenticated attacker can bypass the localhost restrictions posed by the application and utilize this to create arbitrary packages
When oxenstored is tearing a domain down, the node data is cleaned up but the usage counts are leaked. When …
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Insecure handling of …