Incorrect Authorization Affecting github.com/openfga/openfga/pkg/storage package, versions >=1.8.5 <1.11.3


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.31% (23rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Incorrect Authorization vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-GOLANG-GITHUBCOMOPENFGAOPENFGAPKGSTORAGE-15243907
  • published6 Feb 2026
  • disclosed5 Feb 2026
  • creditUnknown

Introduced: 5 Feb 2026

CVE-2026-24851  (opens in a new tab)
CWE-863  (opens in a new tab)

How to fix?

Upgrade github.com/openfga/openfga/pkg/storage to version 1.11.3 or higher.

Overview

Affected versions of this package are vulnerable to Incorrect Authorization when certain Check calls are executed. An attacker can gain unauthorized access to resources by exploiting improper policy enforcement when specific conditions involving type bound public and non-public access relations, tuple assignments, and object ID ordering are met.

Note:

This is only exploitable if the model has a relation directly assignable by both type bound public and non-public access, a tuple is assigned for the relation as type bound public access, another tuple is assigned for the same object and relation as non-public access, and a tuple is assigned for a different object with a lexicographically larger object ID for the same user and relation as non-public access.

References

CVSS Base Scores

version 4.0
version 3.1