Improper Authentication in FalkorDB Prior to Version 4.20.0
CVE-2026-107910

9.2CRITICAL

Key Information:

Vendor

Falkordb

Status
Vendor
CVE Published:
9 October 2026

What is CVE-2026-107910?

An improper authentication issue exists in FalkorDB prior to version 4.20.0, allowing remote unauthorized users to execute graph queries via the Bolt endpoint. This flaw arises from the is_authenticated function, which incorrectly interprets certain Redis errors. Instead of requiring valid authentication credentials, the system mistakenly grants access under specific error conditions. Only instances where the Bolt endpoint is enabled are susceptible to this vulnerability, making it crucial for users to review their configurations and apply necessary updates.

Affected Version(s)

FalkorDB 0 < 4.20.0

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Arjun Basnet from Securin
.