Description
OpenFGA is an authorization and permission engine built for developers. Prior to 1.18.1, the ListUsers API could return a user that should have been excluded when an authorization relation used an intersection containing a base but not excluded operand, the base was granted through a type-bound public wildcard, and the excluded user also had a concrete tuple through another intersection operand. In pkg/server/commands/listusers/list_users_rpc.go, expandIntersection counted the concrete tuple and wildcard without first rejecting entries in excludedUsersMap. Applications that used ListUsers to enumerate or enforce access could therefore treat an excluded user as authorized. This issue is fixed in version 1.18.1.
Published: 2026-09-16
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authorization over‑inclusion (unauthorized users exposed)
Action: Patch
AI Analysis

Impact

The ListUsers API in OpenFGA contains a logical flaw that allows a user who should be excluded by a "but not" rule to be returned when the rule includes an intersection between a type‑bound public wildcard and another relation that grants that user. The code path responsible for rejecting excluded users is bypassed during tuple expansion, so the caller receives a user that is not authorized. This mis‑classification can expose the existence of users or allow an application to treat the returned user as having valid access, potentially enabling further enumeration or misuse of resources.

Affected Systems

The vulnerability exists in the OpenFGA authorization engine provided by the vendor OpenFGA. Any deployment using a version older than 1.18.1 is affected, regardless of the operating environment or hosting platform.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, and the EPSS score of < 1% signifies a low likelihood of exploitation at present. The issue is not listed in the CISA KEV catalog. An attacker must be able to invoke the ListUsers API, which typically requires either exposure of the endpoint or compromise of a client with permission to call it. No privilege escalation or remote code execution is necessary; the risk lies in unauthorized disclosure or enumeration of users.

Generated by OpenCVE AI on September 18, 2026 at 03:14 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade OpenFGA to version 1.18.1 or later.
  • Restrict or secure the ListUsers API endpoint so that only trusted clients or internal services can call it, disabling or protecting the interface if it is not required publicly.
  • Validate that excluded users are not returned by running integration tests that query ListUsers for known excluded users and confirm they are omitted from the response.
  • Review and audit logs of ListUsers calls to detect any unintended exposure of excluded users.

Generated by OpenCVE AI on September 18, 2026 at 03:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-g3pg-frfm-pr2m OpenFGA: ListUsers returns a deliberately-excluded user when a `but not` exclusion under a type-bound wildcard is intersected (`and`) with another relation that also grants that user
History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-783
References
Metrics threat_severity

None

threat_severity

Moderate


Thu, 17 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Openfga
Openfga openfga
Vendors & Products Openfga
Openfga openfga

Wed, 16 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description OpenFGA is an authorization and permission engine built for developers. Prior to 1.18.1, the ListUsers API could return a user that should have been excluded when an authorization relation used an intersection containing a base but not excluded operand, the base was granted through a type-bound public wildcard, and the excluded user also had a concrete tuple through another intersection operand. In pkg/server/commands/listusers/list_users_rpc.go, expandIntersection counted the concrete tuple and wildcard without first rejecting entries in excludedUsersMap. Applications that used ListUsers to enumerate or enforce access could therefore treat an excluded user as authorized. This issue is fixed in version 1.18.1.
Title OpenFGA: ListUsers returns a deliberately-excluded user (authorization-decision over-inclusion) when a `but not` exclusion under a type-bound wildcard is intersected (`and`) with another relation that also grants that user
Weaknesses CWE-281
CWE-863
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-18T17:52:34.349Z

Reserved: 2026-07-10T18:51:13.919Z

Link: CVE-2026-61709

cve-icon Vulnrichment

Updated: 2026-09-18T17:52:29.204Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T15:17:39.660

Modified: 2026-09-24T21:25:27.050

Link: CVE-2026-61709

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-16T14:05:35Z

Links: CVE-2026-61709 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T03:15:02Z

Weaknesses
  • CWE-281

    Improper Preservation of Permissions

  • CWE-783

    Operator Precedence Logic Error

  • CWE-863

    Incorrect Authorization