Skip to main content
EPSS 0.3%top 85%

Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update

0
High
Published: 09/18/2026 (09/18/2026, 08:52:34 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

A security flaw (CVE-2026-61709) was found in OpenFGA's ListUsers API, which could incorrectly return users who should have been excluded from authorization decisions when complex rules with exclusions and type-bound wildcards are used. This vulnerability affects the OpenFGA code bundled in Grafana's experimental Zanzana authorization engine, which is embedded in several Red Hat products. The vulnerable API is not used in Grafana's main authorization path and Zanzana is disabled by default. No product-side mitigation is required if Zanzana remains disabled. If enabled, users should avoid using ListUsers for access control decisions and instead use the Check API until a fixed OpenFGA version 1.18.1 or later is available.

Affected software

Affected versions
Red HatRed Hat Hardened Imagesaarch64grafana12.4-0:12.4.10-0.6.hum1@aarch64

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/29/2026, 04:46:04 UTC

Technical Analysis

CVE-2026-61709 is a vulnerability in OpenFGA's ListUsers API where the API may return users that should have been excluded by a but-not clause when an intersection uses a type-bound public wildcard. This can lead to unauthorized access in applications relying on ListUsers for access control. Red Hat does not ship OpenFGA standalone; it is bundled in Grafana's experimental Zanzana engine, which is embedded in Red Hat Ceph Storage dashboards, Red Hat Advanced Cluster Management, Multicluster Global Hub, and the RHEL grafana package. Zanzana is disabled by default and Grafana's main authorization uses different APIs (Check and ListObjects), so the vulnerable API is not the enforcement path in these products. The vulnerability is fixed in OpenFGA version 1.18.1. Red Hat provides updated RPMs for grafana12.4 including this fix.

Potential Impact

Applications relying on the vulnerable ListUsers API for access control decisions might inadvertently grant unauthorized access to resources or sensitive information due to incorrect user exclusion logic. However, since the vulnerable API is part of an experimental engine (Zanzana) that is disabled by default and not used in Grafana's main authorization path, the practical impact on Red Hat products is limited unless Zanzana is explicitly enabled.

Mitigation Recommendations

No product-side mitigation is required while Zanzana remains disabled, which is the default setting. If Zanzana has been enabled, do not use ListUsers results for access control decisions; instead, use the Check API for each user and object. Apply the update to OpenFGA version 1.18.1 or later when it becomes available in Grafana. Red Hat has released updated grafana12.4 RPMs containing the fix. Refer to Red Hat advisory RHSA-2026:68821 for update instructions.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:68821
Cve Count
14
Additional Cves
["CVE-2026-28376","CVE-2026-28379","CVE-2026-28380","CVE-2026-28383","CVE-2026-33376","CVE-2026-33377","CVE-2026-33378","CVE-2026-33380","CVE-2026-33381","CVE-2026-61709","CVE-2026-81871","CVE-2026-81872","CVE-2026-92599"]
State
PUBLISHED

Threat ID: 6abb4184f7a7c54106cc2ed7

Added to database: 09/29/2026, 04:41:40 UTC

Last enriched: 09/29/2026, 04:46:04 UTC

Last updated: 09/29/2026, 18:13:10 UTC

Views: 3

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses