Sceawere
Vulnerability Detail
CVE-2026-107910UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
FalkorDB Improper Authentication Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.1
- Creation Date
- 4h ago
- Vendor
- FalkorDB
- Product
- FalkorDB
- Attack Type
- CWE-287 Improper Authentication
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
An improper authentication vulnerability in the is_authenticated function (src/bolt/bolt_api.c) in FalkorDB before 4.20.0 allows a remote unauthenticated attacker to execute graph queries without credentials through the Bolt endpoint. The function decides whether a password is required by issuing an empty AUTH command to Redis and treats only a WRONGPASS error as meaning that a password is required; any other error, such as LOADING while a dataset is being loaded, MASTERDOWN during replication failover, or OOM under memory pressure, causes the client to be treated as authenticated. Only deployments that enable the Bolt endpoint (BOLT_PORT, disabled by default) are affected.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.1",
"pubDate": "2026-10-09T06:17:12.457Z",
"pubdate": "2026-10-09T06:17:12.457Z",
"executiveSummary": "FalkorDB versions prior to 4.20.0 contain an improper authentication vulnerability in the is_authenticated function within src/bolt/bolt_api.c. The vulnerability allows remote, unauthenticated attackers to bypass authentication requirements on the Bolt endpoint.\nThe flaw stems from an insecure implementation of credential verification logic, which mistakenly treats various Redis operational error states as successful authentication conditions. By triggering specific server-side errors, an attacker can bypass the password check and execute arbitrary graph queries without valid credentials.\nThis vulnerability is limited to deployments where the Bolt endpoint (BOLT_PORT) is explicitly enabled, as it is disabled by default. Successful exploitation grants an attacker full access to query the database, potentially leading to unauthorized data disclosure, modification, or deletion, depending on the graph's configured permissions. The risk is high for internet-facing instances where the Bolt port is exposed, as it requires no prior authentication or specialized privileges.",
"technicalDetails": "The root cause of this vulnerability lies in the logic contained within the is_authenticated function in src/bolt/bolt_api.c, which manages authentication state for the Bolt protocol. When a client initiates a connection, the function attempts to verify the session by sending an empty AUTH command to the underlying Redis instance.\nThe implementation adopts a flawed verification strategy: it explicitly checks for a 'WRONGPASS' error response from Redis to determine if a password is required. If the Redis server returns any response other than 'WRONGPASS', the code incorrectly assumes the authentication request was successful or unnecessary. This logic fails to account for other standard Redis error responses, such as 'LOADING' (during dataset startup), 'MASTERDOWN' (during replication failover), or 'OOM' (out-of-memory conditions).\nUnder these specific operational states, the Redis server returns an error message that does not match 'WRONGPASS'. Consequently, the is_authenticated function incorrectly grants the client an authenticated status despite the absence of valid credentials. An attacker can deliberately trigger or wait for these specific server conditions to bypass the security check.\nThe attack flow proceeds as follows: 1) The attacker identifies a target FalkorDB deployment where the BOLT_PORT is exposed. 2) The attacker sends an initial Bolt handshake. 3) The attacker monitors or forces the backend Redis instance into a non-WRONGPASS error state (e.g., during a node reboot or under artificial memory pressure). 4) Upon encountering an error such as 'LOADING', the is_authenticated function executes its fallback logic, marking the connection as authenticated. 5) Once the session is flagged as authenticated, the attacker gains the ability to execute arbitrary graph queries through the Bolt endpoint. 6) The impact is significant, as the attacker essentially circumvents the entire authentication layer, potentially executing unauthorized read or write operations against the graph data. This flaw effectively turns a protected interface into an open gateway whenever the Redis backend is busy or undergoing state transitions, bypassing the intended security controls defined for the Bolt endpoint."
}