Description
An improper authentication vulnerability in the is_authenticated function (src/bolt/bolt_api.c) in FalkorDB before 4.20.0 allows a remote unauthenticated attacker to execute graph queries without credentials through the Bolt endpoint. The function decides whether a password is required by issuing an empty AUTH command to Redis and treats only a WRONGPASS error as meaning that a password is required; any other error, such as LOADING while a dataset is being loaded, MASTERDOWN during replication failover, or OOM under memory pressure, causes the client to be treated as authenticated. Only deployments that enable the Bolt endpoint (BOLT_PORT, disabled by default) are affected.
Published: 2026-10-09
Score: 9.2 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Solution

Upgrade FalkorDB to version 4.20.0 or later. Bolt protocol support, including the code affected by this issue, was removed in 4.20.0.


Vendor Workaround

Leave the Bolt endpoint disabled (do not set the BOLT_PORT module configuration; it is disabled by default), or restrict network access to the Bolt port to trusted clients.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 05:30:00 +0000

Type Values Removed Values Added
Description An improper authentication vulnerability in the is_authenticated function (src/bolt/bolt_api.c) in FalkorDB before 4.20.0 allows a remote unauthenticated attacker to execute graph queries without credentials through the Bolt endpoint. The function decides whether a password is required by issuing an empty AUTH command to Redis and treats only a WRONGPASS error as meaning that a password is required; any other error, such as LOADING while a dataset is being loaded, MASTERDOWN during replication failover, or OOM under memory pressure, causes the client to be treated as authenticated. Only deployments that enable the Bolt endpoint (BOLT_PORT, disabled by default) are affected.
Title Authentication bypass in FalkorDB Bolt endpoint via fail-open AUTH probe error handling
First Time appeared Falkordb
Falkordb falkordb
Weaknesses CWE-287
CPEs cpe:2.3:a:falkordb:falkordb:*:*:*:*:*:*:*:*
Vendors & Products Falkordb
Falkordb falkordb
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Falkordb Falkordb
cve-icon MITRE

Status: PUBLISHED

Assigner: securin

Published:

Updated: 2026-10-09T05:08:13.092Z

Reserved: 2026-10-09T04:54:55.521Z

Link: CVE-2026-107910

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-09T06:17:12.457

Modified: 2026-10-09T06:17:12.577

Link: CVE-2026-107910

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T06:30:17Z

Weaknesses