CVE-2026-42072General

LOWCVSS 9.8 · CRITICAL

Signal is active with 5 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Nornicdb is a distributed low-latency, Graph+Vector, Temporal MVCC with all sub-ms HNSW search, graph traversal, and writes. Prior to version 1.0.42-hotfix, the --address CLI flag (and NORNICDB_ADDRESS / server.host config key) is plumbed through to the HTTP server correctly but never reaches the Bolt server config. The Bolt listener therefore always binds to the wildcard address (all interfaces), regardless of what the user configures. On a LAN, this exposes the graph database — with its default admin:password credentials — to any device sharing the network. This issue has been patched in version 1.0.42-hotfix.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1392

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • General: 3 classified signals
  • Disclosure: 2 classified signals
  • Peaked at 5 mentions on most recent observed day (2026-05-13)
  • 6 total mentions across 2 days

Deep dive

Activity timeline6 mentions / 2d
01345Mentions · 2026-05-08: 1Mentions · 2026-05-13: 5Patch / Workaround · 2026-05-08: 1Technical Details · 2026-05-13: 305-0805-13
Signal classification3 categories
General
350.0%
Disclosure
233.3%
Patch
116.7%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-081
Patch1
2026-05-135
Disclosure2General3
Full discourse6 posts
  • Lyrie.ai@lyrie_ai
    General

    References CVE: CVE-2026-42072 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The brief notice identifies CVE‑2026‑42072 as a critical vulnerability but provides no further technical detail, exploitation evidence, or mitigation guidance.

    1000030
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE: CVE-2026-42072 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory Nornicdb is a distributed low-latency, Graph+Vector, Temporal MVCC with all sub-ms HNSW search, graph traversal, and writes.

    Post summary

    A critical advisory for CVE-2026-42072 is issued with CVSS 9.8, but no exploitation details, PoC, or patch information are provided.

    1000028
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    --- Validated by the Lyrie Threat Intelligence Pipeline — 3 independent sources confirmed before publication. No speculation. CVE: CVE-2026-42072 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The text announces CVE‑2026‑42072 as a critical vulnerability, providing its CVSS score, vector, and severity details.

    1000037
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    CRITICAL: CVE-2026-42072 (CVSS 9.8) — multiple products. CVE: CVE-2026-42072 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The post lists the CVE’s critical severity and CVSS score but otherwise provides no details on PoC, exploit, or mitigation.

    1000029
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-42072-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The excerpt only references a URL pointing to a CVE-2026-42072 advisory, providing no explicit detail on PoC, exploits, patches, or technical specifics.

    0000020
    210 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-42072 Nornicdb is a distributed low-latency, Graph+Vector, Temporal MVCC with all sub-ms HNSW search, graph traversal, and writes. Prior to version 1.0.42-hotfix, the --add… https://www.cve.org/CVERecord?id=CVE-2026-42072

    Post summary

    The tweet references a CVE affecting Nornicdb that is apparently addressed by a hotfix in version 1.0.42; no proof of concept, exploit, or active exploitation details are provided.

    0000050
    57.5K followersView on X

Explore more