Vulnerability in Nornicdb Graph Database Allows Unauthorized Access to All Interfaces
CVE-2026-42072

9.8CRITICAL

Key Information:

Vendor

Orneryd

Status
Vendor
CVE Published:
8 May 2026

What is CVE-2026-42072?

The Nornicdb graph database contains a vulnerability that allows the Bolt listener to bind to all network interfaces, exposing the service to unauthorized access on local networks. This occurs due to the misconfiguration of the --address CLI flag, which fails to correctly apply user settings to the Bolt server configurations. As a result, devices on the same network can gain access to the database with default admin credentials. Users are encouraged to upgrade to version 1.0.42-hotfix to mitigate this security risk.

Affected Version(s)

NornicDB < 1.0.42-hotfix

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.