Unauthenticated Runtime Configuration Exposure in NebulaGraph by Vesoft
CVE-2026-81032
What is CVE-2026-81032?
NebulaGraph by Vesoft has a security vulnerability that allows an unauthenticated HTTP service to expose its runtime configurations. Each daemon starts a web service that opens access to all interfaces, meaning that sensitive information, such as certificate paths, password files, and security flags, can be retrieved without any authentication. Furthermore, the service allows for modifications to the daemon's settings through an insecure write route, enabling unauthorized users to change critical configurations, like disabling security measures. This vulnerability can lead to serious implications, including unauthorized data access and manipulation of service parameters. Users are encouraged to update to the latest version and implement proper access controls.
Affected Version(s)
nebula 0 <= 3.8.0
