OpenFGA is a high-performance and flexible authorization/permission engine. Some end users of OpenFGA v1.5.0 or later are vulnerable to authorization bypass when calling Check or ListObjects APIs. You are very likely affected if your model involves exclusion (e.g. `a but not b`) or intersection (e.g. `a and b`). This vulnerability is fixed in v1.5.3.
Cite this page
CVE-2024-31452. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2024-31452
Use CWE-863, Openfga vendor hub and Openfga product page to widen CVE-2024-31452 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2024-42473, CVE-2026-40293 and CVE-2026-33729 for nearby disclosures in the same product family.