Unauthenticated Runtime Configuration Exposure in NebulaGraph by Vesoft
CVE-2026-81032

9.3CRITICAL

Key Information:

Vendor

Vesoft-inc

Status
Vendor
CVE Published:
26 August 2026

What is CVE-2026-81032?

NebulaGraph by Vesoft has a security vulnerability that allows an unauthenticated HTTP service to expose its runtime configurations. Each daemon starts a web service that opens access to all interfaces, meaning that sensitive information, such as certificate paths, password files, and security flags, can be retrieved without any authentication. Furthermore, the service allows for modifications to the daemon's settings through an insecure write route, enabling unauthorized users to change critical configurations, like disabling security measures. This vulnerability can lead to serious implications, including unauthorized data access and manipulation of service parameters. Users are encouraged to update to the latest version and implement proper access controls.

Affected Version(s)

nebula 0 <= 3.8.0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.