CVE-2026-24851

HIGH

OpenFGA 1.8.5-1.11.2 - Incorrect Authorization via Check Call Policy Enforcement

Title source: llm
STIX 2.1

Description

OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.8.5 to v1.11.2 ( openfga-0.2.22<= Helm chart <= openfga-0.2.51, v.1.8.5 <= docker <= v.1.11.2) are vulnerable to improper policy enforcement when certain Check calls are executed. The vulnerability requires a model that has a a relation directly assignable by a type bound public access and assignable by type bound non-public access, a tuple assigned for the relation that is a type bound public access, a tuple assigned for the same object with the same relation that is not type bound public access, and a tuple assigned for a different object that has an object ID lexicographically larger with the same user and relation which is not type bound public access. This vulnerability is fixed in v1.11.3.

References (2)

Core 2
Core References

Scores

CVSS v3 8.8
EPSS 0.0031
EPSS Percentile 22.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (3)
openfga/helm_charts 0.2.22 - 0.2.51
openfga/openfga 1.8.5 - 1.11.3Go
openfga/openfga 1.8.5 - 1.11.3
Published Feb 06, 2026
Tracked Since Feb 18, 2026