Improper Authentication in FalkorDB Prior to Version 4.20.0
CVE-2026-107910
9.2CRITICAL
What is CVE-2026-107910?
An improper authentication issue exists in FalkorDB prior to version 4.20.0, allowing remote unauthorized users to execute graph queries via the Bolt endpoint. This flaw arises from the is_authenticated function, which incorrectly interprets certain Redis errors. Instead of requiring valid authentication credentials, the system mistakenly grants access under specific error conditions. Only instances where the Bolt endpoint is enabled are susceptible to this vulnerability, making it crucial for users to review their configurations and apply necessary updates.
Affected Version(s)
FalkorDB 0 < 4.20.0
