CVE-2026-24851·Docker vulnerability
OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.8.5 to v1.11.2 ( openfga-0.2.22<= Helm chart <= openfga-0.2.51, v.1.8.5 <= docker <= v.1.11.2) are vulnerable to improper policy enforcement when certain Check calls are executed. The vulnerability requires a model that has a a relation directly assignable by a type bound public access and assignable by type bound non-public access, a tuple assigned for the relation that is a type bound public access, a tuple assigned for the same object with the same relation that is not type bound public access, and a tuple assigned for a different object that has an object ID lexicographically larger with the same user and relation which is not type bound public access. This vulnerability is fixed in v1.11.3.
- Severity
- high
- Software
- Docker
- Fixed in
- 1.11.3
- Published
- 2026-02-06
Affected versions
From: 1.8.5
Until: 1.11.3
Fixed in: 1.11.3
How to fix this CVE
Update Docker to version 1.11.3 or later to resolve an authorization bypass vulnerability in OpenFGA's policy enforcement logic. This vulnerability affects Docker installations running OpenFGA versions 1.8.5 through 1.11.2, where specific permission model configurations can lead to improper access control decisions. Immediately patch your Docker installation and validate that access control policies are functioning correctly after the update.
sudo dnf update docker-ce --setopt=install_weak_deps=FalseDefensia detects this vulnerability
How to check if you are affected
- Step 1: Run `docker --version` and `docker version` to confirm installed Docker version; compare against 1.8.5–1.11.2 range to identify vulnerability
- Step 2: Check if OpenFGA is running within Docker by executing `docker ps --filter 'ancestor=openfga*' --format='table {{.Image}}\t{{.Status}}'`
- Step 3: Review Docker daemon logs for authorization failures: `sudo journalctl -u docker -n 1000 | grep -i 'permission\|authorization\|check'`
- Step 4: After patching, verify the new version with `docker --version` and restart the Docker daemon: `sudo systemctl restart docker`
FAQ
What is CVE-2026-24851?
CVE-2026-24851 is an authorization bypass vulnerability in Docker versions running OpenFGA 1.8.5 through 1.11.2. Under specific permission model conditions involving mixed public and non-public type-bound access tuples, the authorization engine may incorrectly grant access to resources that should be denied.
Is CVE-2026-24851 being actively exploited?
No, CVE-2026-24851 is not currently listed in CISA's Known Exploited Vulnerabilities (KEV) catalog and has no public exploit available. However, the high CVSS score (8.8) warrants immediate patching.
What versions of Docker are affected by CVE-2026-24851?
Docker versions 1.8.5 through 1.11.2 are vulnerable; Helm chart versions openfga-0.2.22 through openfga-0.2.51 are also affected. The fix is available in version 1.11.3 and later.
How do I check if my server is vulnerable to CVE-2026-24851?
Run `docker --version` and check if the version falls within 1.8.5–1.11.2. Additionally, inspect your authorization model configuration to confirm it matches the vulnerable pattern: a relation with both public type-bound and non-public type-bound assignments.
Does Defensia detect CVE-2026-24851?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Docker is installed on a monitored server, CVE-2026-24851 will appear in your dashboard with remediation steps.
Related Docker CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-24851. Free for 1 server.
Get started free