Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update
A security flaw (CVE-2026-61709) was found in OpenFGA's ListUsers API, which could incorrectly return users who should have been excluded from authorization decisions when complex rules with exclusions and type-bound wildcards are used. This vulnerability affects the OpenFGA code bundled in Grafana's experimental Zanzana authorization engine, which is embedded in several Red Hat products. The vulnerable API is not used in Grafana's main authorization path and Zanzana is disabled by default. No product-side mitigation is required if Zanzana remains disabled. If enabled, users should avoid using ListUsers for access control decisions and instead use the Check API until a fixed OpenFGA version 1.18.1 or later is available.
AI Analysis
Technical Summary
CVE-2026-61709 is a vulnerability in OpenFGA's ListUsers API where the API may return users that should have been excluded by a but-not clause when an intersection uses a type-bound public wildcard. This can lead to unauthorized access in applications relying on ListUsers for access control. Red Hat does not ship OpenFGA standalone; it is bundled in Grafana's experimental Zanzana engine, which is embedded in Red Hat Ceph Storage dashboards, Red Hat Advanced Cluster Management, Multicluster Global Hub, and the RHEL grafana package. Zanzana is disabled by default and Grafana's main authorization uses different APIs (Check and ListObjects), so the vulnerable API is not the enforcement path in these products. The vulnerability is fixed in OpenFGA version 1.18.1. Red Hat provides updated RPMs for grafana12.4 including this fix.
Potential Impact
Applications relying on the vulnerable ListUsers API for access control decisions might inadvertently grant unauthorized access to resources or sensitive information due to incorrect user exclusion logic. However, since the vulnerable API is part of an experimental engine (Zanzana) that is disabled by default and not used in Grafana's main authorization path, the practical impact on Red Hat products is limited unless Zanzana is explicitly enabled.
Mitigation Recommendations
No product-side mitigation is required while Zanzana remains disabled, which is the default setting. If Zanzana has been enabled, do not use ListUsers results for access control decisions; instead, use the Check API for each user and object. Apply the update to OpenFGA version 1.18.1 or later when it becomes available in Grafana. Red Hat has released updated grafana12.4 RPMs containing the fix. Refer to Red Hat advisory RHSA-2026:68821 for update instructions.
Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update
Description
A security flaw (CVE-2026-61709) was found in OpenFGA's ListUsers API, which could incorrectly return users who should have been excluded from authorization decisions when complex rules with exclusions and type-bound wildcards are used. This vulnerability affects the OpenFGA code bundled in Grafana's experimental Zanzana authorization engine, which is embedded in several Red Hat products. The vulnerable API is not used in Grafana's main authorization path and Zanzana is disabled by default. No product-side mitigation is required if Zanzana remains disabled. If enabled, users should avoid using ListUsers for access control decisions and instead use the Check API until a fixed OpenFGA version 1.18.1 or later is available.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-61709 is a vulnerability in OpenFGA's ListUsers API where the API may return users that should have been excluded by a but-not clause when an intersection uses a type-bound public wildcard. This can lead to unauthorized access in applications relying on ListUsers for access control. Red Hat does not ship OpenFGA standalone; it is bundled in Grafana's experimental Zanzana engine, which is embedded in Red Hat Ceph Storage dashboards, Red Hat Advanced Cluster Management, Multicluster Global Hub, and the RHEL grafana package. Zanzana is disabled by default and Grafana's main authorization uses different APIs (Check and ListObjects), so the vulnerable API is not the enforcement path in these products. The vulnerability is fixed in OpenFGA version 1.18.1. Red Hat provides updated RPMs for grafana12.4 including this fix.
Potential Impact
Applications relying on the vulnerable ListUsers API for access control decisions might inadvertently grant unauthorized access to resources or sensitive information due to incorrect user exclusion logic. However, since the vulnerable API is part of an experimental engine (Zanzana) that is disabled by default and not used in Grafana's main authorization path, the practical impact on Red Hat products is limited unless Zanzana is explicitly enabled.
Mitigation Recommendations
No product-side mitigation is required while Zanzana remains disabled, which is the default setting. If Zanzana has been enabled, do not use ListUsers results for access control decisions; instead, use the Check API for each user and object. Apply the update to OpenFGA version 1.18.1 or later when it becomes available in Grafana. Red Hat has released updated grafana12.4 RPMs containing the fix. Refer to Red Hat advisory RHSA-2026:68821 for update instructions.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:68821
- Cve Count
- 14
- Additional Cves
- ["CVE-2026-28376","CVE-2026-28379","CVE-2026-28380","CVE-2026-28383","CVE-2026-33376","CVE-2026-33377","CVE-2026-33378","CVE-2026-33380","CVE-2026-33381","CVE-2026-61709","CVE-2026-81871","CVE-2026-81872","CVE-2026-92599"]
- State
- PUBLISHED
Threat ID: 6abb4184f7a7c54106cc2ed7
Added to database: 09/29/2026, 04:41:40 UTC
Last enriched: 09/29/2026, 04:46:04 UTC
Last updated: 09/29/2026, 18:13:10 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.