Sceawere

Vulnerability Detail

CVE-2026-108710UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

NornicDB Missing Authorization Bypass

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
4h ago
Vendor
orneryd
Product
NornicDB
Attack Type
Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

NornicDB through 1.4.1 contains a missing authorization vulnerability that allows authenticated users to bypass per-database read restrictions on the /nornicdb/search and /nornicdb/similar endpoints. Viewer-role users allowlisted for a database but denied read can submit search queries or node IDs to retrieve node IDs, labels and full property maps.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-10-11T13:17:13.720Z",
  "pubdate": "2026-10-11T13:17:13.720Z",
  "executiveSummary": "NornicDB versions through 1.4.1 are susceptible to a critical missing authorization vulnerability affecting the /nornicdb/search and /nornicdb/similar endpoints.\nThe vulnerability allows authenticated users with restricted 'Viewer' roles to circumvent enforced per-database read access controls.\nBy manipulating requests to these specific API endpoints, an unauthorized actor can perform unauthorized data retrieval operations, including the extraction of node IDs, labels, and comprehensive property maps from databases they are explicitly denied permission to access.\nThis flaw represents a significant risk to data confidentiality and integrity, as it enables low-privileged users to bypass the principle of least privilege, potentially exposing sensitive database content to unauthorized internal actors.\nSuccessful exploitation requires authenticated access to the system, but does not require higher-level administrative privileges, effectively turning a read-restricted user into an unauthorized data consumer for any database hosted within the NornicDB instance.",
  "technicalDetails": "The vulnerability originates from a deficiency in access control logic within the NornicDB application's request handling pipeline for the /nornicdb/search and /nornicdb/similar endpoints. While the application implements a multi-tenant or per-database permission model where 'Viewer' roles can be granularly restricted, these specific endpoints fail to properly validate the requesting user's authorization status against the target database context at the time of execution.\nThe root cause is a failure to perform a robust security check (i.e., an authorization gate) within the service-layer logic responsible for processing search and similarity queries. The backend application logic assumes that if a user is authenticated, they have sufficient scope to query the underlying graph database, failing to verify whether the specific user has been granted read-access to the target database entity identified in the request parameters.\nThe attack flow proceeds as follows: 1) An authenticated attacker with a 'Viewer' role identifies a target database for which they have been denied read permissions. 2) The attacker crafts a request targeting the /nornicdb/search or /nornicdb/similar endpoints. 3) The attacker includes the target database identifier or associated query parameters in the request body or URI. 4) The server receives the request and, due to the missing check, proceeds to execute the query against the database storage engine. 5) The server returns the requested node IDs, metadata labels, and full property map objects to the attacker, despite the existing restriction.\nThis behavior exposes the underlying data store to unauthorized reconnaissance and data scraping. By repeatedly querying the /nornicdb/search endpoint, an attacker can enumerate the structure and content of protected databases. The /nornicdb/similar endpoint may further allow an attacker to traverse graph relationships and discover connected nodes that should be inaccessible based on the user's role configuration. Because this occurs at the application level after initial authentication, the malicious requests appear legitimate to the system, significantly complicating detection through traditional perimeter security controls. The vulnerability exists in all versions of NornicDB up to and including 1.4.1 and does not require complex payloads, only the knowledge of the internal API structure and target database IDs."
}
CVE-2026-108710: NornicDB Missing Authorization Bypass (MEDIUM Severity, CVSS: 6.5) | Sceawere