CVE-2026-41492Disclosure(dgraph / dgraph)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch dgraph dgraph systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, Dgraphl exposes the process command line through the unauthenticated /debug/vars endpoint on Alpha. Because the admin token is commonly supplied via the --security "token=..." startup flag, an unauthenticated attacker can retrieve that token and replay it in the X-Dgraph-AuthToken header to access admin-only endpoints. This is a variant of the previously fixed /debug/pprof/cmdline issue, but the current fix is incomplete because it blocks only /debug/pprof/cmdline and still serves http.DefaultServeMux, which includes expvar's /debug/vars handler. This vulnerability is fixed in 25.3.3.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dgraph

Threat summary

  • Patch or workaround signal is available
  • 9 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 6 signals
  • Disclosure: 7 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 5 mentions (2026-05-22); latest day: 1
  • 9 total mentions across 4 days

Affected systems

Vendors
Products
dgraph

Deep dive

Activity timeline9 mentions / 4d
01345Mentions · 2026-04-24: 2Mentions · 2026-04-25: 1Mentions · 2026-05-22: 5Mentions · 2026-06-11: 1Patch / Workaround · 2026-04-24: 1Patch / Workaround · 2026-05-22: 1Technical Details · 2026-04-24: 1Technical Details · 2026-04-25: 1Technical Details · 2026-05-22: 3Technical Details · 2026-06-11: 104-2404-2505-2206-11
Signal classification3 categories
Disclosure
777.8%
General
111.1%
Patch
111.1%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-242
Disclosure1General1
2026-04-251
Disclosure1
2026-05-225
Disclosure4Patch1
2026-06-111
Disclosure1
Full discourse9 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-41492 - critical 🚨 Dgraph <= 25.3.2 - Admin Token Disclosure > Dgraph <= 25.3.2 contains an information disclosure caused by unauthenticated access ... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-41492 @pdnuclei #NucleiTemplates #cve

    Post summary

    CVE‑2026‑41492 identifies a critical unauthenticated information disclosure in Dgraph <=25.3.2, with no evidence of exploitation, patch, or PoC provided.

    00011139
    958 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    [2] DailyCVE: "Dgraph, Infoleak, CVE-2026-41492 (critical)" Dgraph's Incomplete Security Patch Leaks Admin Tokens: Critical /debug/vars Flaw (CVE-2026-41492)

    Post summary

    The post announces a critical Dgraph vulnerability (CVE‑2026‑41492) that allows admin token leakage via an exposed debug endpoint, but it lacks detailed technical or exploit information.

    10000785
    227 followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    A previous patch to CVE-2026-41328 blocked the /debug/pprof/cmdline endpoint but only via explicit URL matching: Dgraph's Incomplete Security Patch Leaks Admin Tokens: Critical /debug/vars Flaw (CVE-2026-41492)

    Post summary

    The statement notes that a previous patch for CVE-2026-41328 only blocked an endpoint via explicit URL matching, and that Dgraph's incomplete patch leaves a critical /debug/vars flaw (CVE-2026-41492) leaking admin tokens.

    1000058
    227 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Unpopular opinion: The cybersecurity industry is selling you dashboards. Dgraph's Incomplete Security Patch Leaks Admin Tokens: Critical /debug/vars Flaw (CVE-2026-41492)

    Post summary

    CVE‑2026‑41492 is a critical flaw in Dgraph exposing admin tokens via an insecure /debug/vars endpoint, with no PoC, exploit, or patch details present.

    1000057
    227 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    On April 24, 2026, CVE-2026-41492 was disclosed, exposing a critical weakness in Dgraph's authentication model. The vulnerability stems from incomplete remediation of a prior security issue.

    Post summary

    CVE-2026-41492, a critical authentication model flaw in Dgraph, was disclosed on April 24, 2026, with no information on PoC, exploitation, or patch availability.

    1000037
    227 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    24, 2026, — Dgraph's Incomplete Security Patch Leaks Admin Tokens: Critical /debug/vars Flaw (CVE-2026-41492). On April 24, 2026, CVE-2026-41492 was disclosed, exposing a critical weakness in Dgraph's authentication model.

    Post summary

    The note announces the disclosure of CVE-2026-41492, a critical flaw in Dgraph’s authentication due to an incomplete patch, but offers no evidence of exploitation or mitigation.

    1000057
    227 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-41492 Unauthenticated Admin Token Exposure in Dgraph Prior to Version 25.3.3 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41492

    Post summary

    The text provides a brief disclosure about CVE-2026-41492, noting it causes unauthenticated admin token exposure in Dgraph versions before 25.3.3, but does not include PoC, exploit code, or patch information.

    0000056
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-41492 Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, Dgraphl exposes the process command line through the unauthenticated /debug/vars endpoint on A… https://www.cve.org/CVERecord?id=CVE-2026-41492

    Post summary

    The post discloses that CVE-2026-41492 allows unauthenticated visibility of process command lines via the /debug/vars endpoint, a vulnerability fixed in version 25.3.3 of Dgraph.

    0000098
    57.2K followersView on X
  • DailyCVE@dailycve
    General

    🔴 Dgraph, Infoleak, #CVE-2026-41492 (critical) https://dailycve.com/dgraph-infoleak-cve-2026-41492-critical/

    Post summary

    The message merely references CVE-2026-41492 and links to a DailyCVE article, without providing further technical, exploit, or mitigation details.

    0000067
    183 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdgraphdgraph-go-

Explore more