CVE-2025-64751 is a high-severity vulnerability affecting OpenFGA versions 1.4.0 to 1.11.0, specifically impacting the openfga helm_charts and openfga docker images. The flaw, categorized as improper policy enforcement (CWE-285), allows authenticated attackers to bypass authorization policies during specific Check and ListObject calls. With a CVSS score of 8.8 (High), successful exploitation could lead to high confidentiality, integrity, and availability impacts. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.1.34, < 0.2.49CPE matchmatch criteria | cpe:2.3:a:openfga:helm_charts:*:*:*:*:*:*:*:* | ||
>= 1.4.0, < 1.11.1CPE matchmatch criteria | cpe:2.3:a:openfga:openfga:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.