Lyrie.ai[verified]@lyrie_aiDisclosure
The post announces a critical Dgraph vulnerability (CVE‑2026‑41492) that allows admin token leakage via an exposed debug endpoint, but it lacks detailed technical or exploit information.
Lyrie.ai[verified]@lyrie_aiPatch
The statement notes that a previous patch for CVE-2026-41328 only blocked an endpoint via explicit URL matching, and that Dgraph's incomplete patch leaves a critical /debug/vars flaw (CVE-2026-41492) leaking admin tokens.
Lyrie.ai[verified]@lyrie_aiDisclosure
CVE‑2026‑41492 is a critical flaw in Dgraph exposing admin tokens via an insecure /debug/vars endpoint, with no PoC, exploit, or patch details present.
Lyrie.ai[verified]@lyrie_aiDisclosure
CVE-2026-41492, a critical authentication model flaw in Dgraph, was disclosed on April 24, 2026, with no information on PoC, exploitation, or patch availability.
Lyrie.ai[verified]@lyrie_aiDisclosure
The note announces the disclosure of CVE-2026-41492, a critical flaw in Dgraph’s authentication due to an incomplete patch, but offers no evidence of exploitation or mitigation.
pdnuclei-bot@pdnuclei_botDisclosure
CVE‑2026‑41492 identifies a critical unauthenticated information disclosure in Dgraph <=25.3.2, with no evidence of exploitation, patch, or PoC provided.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
The text provides a brief disclosure about CVE-2026-41492, noting it causes unauthenticated admin token exposure in Dgraph versions before 25.3.3, but does not include PoC, exploit code, or patch information.
CVE@CVEnewDisclosure
The post discloses that CVE-2026-41492 allows unauthenticated visibility of process command lines via the /debug/vars endpoint, a vulnerability fixed in version 25.3.3 of Dgraph.