Vulnerability in Nornicdb Graph Database Allows Unauthorized Access to All Interfaces
CVE-2026-42072
9.8CRITICAL
What is CVE-2026-42072?
The Nornicdb graph database contains a vulnerability that allows the Bolt listener to bind to all network interfaces, exposing the service to unauthorized access on local networks. This occurs due to the misconfiguration of the --address CLI flag, which fails to correctly apply user settings to the Bolt server configurations. As a result, devices on the same network can gain access to the database with default admin credentials. Users are encouraged to upgrade to version 1.0.42-hotfix to mitigate this security risk.
Affected Version(s)
NornicDB < 1.0.42-hotfix
