Skip to content
Vulnerabilities

Orgs with FalkorDB Bolt Endpoint Exposed Face Critical Auth Bypass CVE-2026-107910

A critical flaw in FalkorDB allows remote users to run queries without credentials if the Bolt endpoint is enabled.

Orgs with FalkorDB Bolt Endpoint Exposed Face Critical Auth Bypass CVE-2026-107910
Illustration: Malware Brief

Key points

  • CVE-2026-107910 is rated critical with a CVSS score of 9.2.
  • The vulnerability exists in FalkorDB versions prior to 4.20.0.
  • Only deployments with the Bolt endpoint enabled are at risk.

Organisations using FalkorDB face a critical authentication bypass that allows unauthenticated remote attackers to execute graph queries. The flaw, tracked as CVE-2026-107910, carries a CVSS score of 9.2, indicating severe potential impact on data integrity and confidentiality.

The vulnerability stems from improper authentication logic within the is_authenticated function located in the Bolt API source code. According to the National Vulnerability Database, this defect allows attackers to circumvent credential checks entirely when specific conditions are met.

How it unfolded

  • The is_authenticated function in src/bolt/bolt_api.c sends an empty AUTH command to Redis to determine if a password is required.
  • The code treats only a WRONGPASS error as a signal that authentication is necessary, ignoring other error types.
  • Errors such as LOADING, MASTERDOWN, or OOM cause the system to incorrectly treat the client as authenticated.

Who is affected

FalkorDB versions before 4.20.0 are vulnerable to this issue. However, the National Vulnerability Database notes that only deployments which have explicitly enabled the Bolt endpoint via the BOLT_PORT setting are affected. This endpoint is disabled by default, limiting the immediate attack surface for standard installations.

The flaw relates to CWE-287, which covers improper authentication mechanisms. Attackers can exploit this by connecting to the Bolt endpoint and triggering conditions that generate non-WRONGPASS errors, such as memory pressure or replication failovers, thereby gaining authorised access without valid credentials.

The fix

The vendor has released version 4.20.0, which addresses the improper authentication logic in the Bolt API. Users running older versions of FalkorDB should upgrade to this version or later to mitigate the risk of unauthenticated query execution.

Until updates are applied, administrators can reduce exposure by ensuring the Bolt endpoint remains disabled if it is not required for their specific operational needs. This configuration change effectively removes the attack vector associated with CVE-2026-107910.

What to do and how to stay safe: FalkorDB

  • Review FalkorDB configurations to ensure the Bolt endpoint is disabled unless strictly necessary for application functionality.
  • Upgrade FalkorDB installations to version 4.20.0 or later to patch the authentication bypass vulnerability.
  • Monitor network logs for unauthorised access attempts to the Bolt port, particularly during periods of system stress.
  • Implement network segmentation to restrict access to the Bolt endpoint from untrusted networks or external sources.

Step-by-step guide: Patch Management: Eight Questions Answered for Stability

General security guidance from the Malware Brief newsroom. It is not confirmed advice from the organisations named in this story.

Frequently asked questions

What is the CVSS score for CVE-2026-107910?

The vulnerability has a CVSS score of 9.2, which is classified as critical.

Does this affect all FalkorDB installations?

No, only installations that have enabled the Bolt endpoint are affected, as it is disabled by default.

Which FalkorDB versions are vulnerable?

All versions of FalkorDB prior to 4.20.0 are affected by this authentication bypass flaw.

Sources

  1. CVE Program
FalkorDBCVE-2026-107910Bolt endpointauthentication bypassgraph database

Related stories

Cybersecurity news without the noiseDaily Briefing