Impact
The ListUsers API in OpenFGA contains a logical flaw that allows a user who should be excluded by a "but not" rule to be returned when the rule includes an intersection between a type‑bound public wildcard and another relation that grants that user. The code path responsible for rejecting excluded users is bypassed during tuple expansion, so the caller receives a user that is not authorized. This mis‑classification can expose the existence of users or allow an application to treat the returned user as having valid access, potentially enabling further enumeration or misuse of resources.
Affected Systems
The vulnerability exists in the OpenFGA authorization engine provided by the vendor OpenFGA. Any deployment using a version older than 1.18.1 is affected, regardless of the operating environment or hosting platform.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score of < 1% signifies a low likelihood of exploitation at present. The issue is not listed in the CISA KEV catalog. An attacker must be able to invoke the ListUsers API, which typically requires either exposure of the endpoint or compromise of a client with permission to call it. No privilege escalation or remote code execution is necessary; the risk lies in unauthorized disclosure or enumeration of users.
OpenCVE Enrichment
Github GHSA