OpenFGA Improper Policy Enforcement Vulnerability Allowing Authorization Issues

Vulnerability

A vulnerability exists in OpenFGA versions 1.4.0 prior to 1.11.0, including specific Helm chart and Docker package versions, due to improper policy enforcement. This issue arises when certain Check and ListObject calls are made, potentially leading to authorization problems by allowing unintended access or permissions.

Impact

Exploitation of this vulnerability could result in improper authorization checks, allowing users to bypass certain access controls or permissions. This could lead to unauthorized actions or access within the application.

Remediation

Users can upgrade to OpenFGA version 1.11.1, which addresses this vulnerability. This upgrade is backwards compatible.

Added: Nov 21, 2025, 2:18 AM
Updated: Nov 21, 2025, 2:18 AM

Vulnerability Rating

Custom Algorithm
spread
1.4
impact
7.5
exploitability
4.5
remediation
7.7
relevance
1.1
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.