vulns.co
/
GKData.io MCP

OpenFGA · 1 min read

OpenFGA: policy intersections must preserve explicit exclusions

CVE-2026-61709 describes incorrect authorization-policy evaluation in user enumeration. Under a particular composition of wildcard membership, exclusion and intersection, a user denied by one policy component could reappear in the result through another component. The failed boundary is preservation of explicit denial when combining permission sets.

Open the reference Maintainer AdvisoryReviewed 2026-10-03

How to use this reference

Editorial lesson: reason about policy results as complete sets, including exclusions, rather than merging positive membership alone. Design contained regression cases that compare composed policy outcomes with their intended semantics. The maintainer recommends OpenFGA 1.18.1 or later and lists Helm chart 0.3.10 as patched.

Before reading

  • Basic object-level authorization and policy-composition concepts

Context and limits

  • Applies when an application relies on ListUsers and its model combines a wildcard-based exclusion with an intersected relation that explicitly grants the excluded user. This does not establish that all models or authorization APIs are affected.
  • The advisory establishes an incorrect result; downstream unauthorized disclosure depends on application use. No production incident or independently verified impact is reported.
  • Published July 16, 2026 by justincoh; reporter 5ud0er is credited. Affected OpenFGA versions are listed through 1.18.0, Helm charts through 0.3.9. Patch release dates and resource-edition dates are not established.

Sources and provenance

  1. OpenFGA Improper Policy Enforcement OpenFGA · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software