External risk intelligence

FalkorDB Bolt Endpoint Authentication Bypass

CVE advisorySeverity: CRITICAL (CVSS 9.2)

CVE-2026-107910

The vulnerability affects the Bolt protocol endpoint, which is disabled by default in FalkorDB. While it is a network-accessible service, it is typically intended for internal database communication rather than public-facing exposure. Because it is not enabled by default and is commonly used in backend infrastructure, internet exposure is plausible but not a standard deployment pattern.

Authentication Bypass

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

An improper authentication vulnerability exists in FalkorDB's Bolt endpoint, potentially allowing unauthenticated remote attackers to execute graph queries. This issue arises from how the system handles authentication errors, incorrectly treating certain operational errors as successful authentication. While the Bolt endpoint is disabled by default, its enablement would expose this vulnerability.

  • Unauthenticated access to graph queries.
  • Enables unauthorized data interaction.
  • Confirm relevance and assess exposure.

Attack Path

How an attacker could exploit the issue

An attacker can remotely send unauthenticated requests to FalkorDB's Bolt endpoint if it is enabled. The system incorrectly assumes authentication based on certain network or loading errors when it should require proper credentials, allowing the attacker to execute graph queries.

  • Network access to enabled Bolt endpoint.
  • Empty AUTH command triggers misauthentication.
  • Unauthenticated graph query execution.

Live Threat

Current exploitation, exposure, and threat context

When the Bolt endpoint is enabled, an unauthenticated remote attacker could execute arbitrary graph queries by exploiting an improper authentication flaw in the `is_authenticated` function. This could occur during specific conditions such as dataset loading, replication failover, or when the system is under memory pressure, which can cause the function to incorrectly identify the attacker as authenticated.

  • Graph queries could be executed.
  • Flawed authentication logic is exploited.
  • Unauthorized system access may occur.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability impacts FalkorDB deployments that have enabled the Bolt endpoint. Initial triage should focus on identifying these deployments, assessing their exposure and criticality, and confirming the accountable owner within the platform or infrastructure teams. Remediation planning should then be prioritized based on this risk assessment.

  • Identify Bolt endpoint usage and ownership.
  • Verify business criticality and network exposure.
  • Plan remediation based on risk and impact.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is FalkorDB and how is it used?

FalkorDB is a high-performance graph database designed to manage and query complex, highly connected data. It uses the Bolt protocol to handle communications between applications and the database, allowing developers to store relationships efficiently and run graph-based queries at scale for applications that require deep link analysis.

What is the vulnerability in CVE-2026-107910?

This is an improper authentication vulnerability (CWE-287). The software incorrectly determines if a user is authenticated by misinterpreting certain database errors. Instead of requiring a password, the system mistakenly treats specific operational states—like when the database is loading data or busy—as a signal that a user is successfully authorized to run graph queries.

How can an attacker trigger this authentication flaw?

An attacker can trigger this by sending an empty authentication command to the Bolt endpoint. The bug only occurs when the database returns specific non-authentication errors, such as memory pressure or replication failover, causing the logic to bypass security. If the system is operating normally and returns a proper password error, the bypass is not triggered.

Is my FalkorDB instance at risk according to Halo Surface Signal?

Risk depends on your configuration. Halo Surface Signal notes that the vulnerable Bolt endpoint is disabled by default. If your deployment has manually enabled this port, it is at risk. While typically used for internal backend traffic, you should verify if your instance is inadvertently reachable via the internet, as that increases your surface area.

What should I do to secure my environment?

Begin by auditing your infrastructure to confirm if the Bolt endpoint is enabled. If it is, evaluate whether this access is strictly necessary for your operations. Coordinate with your team to prioritize updating to version 4.20.0 or later, which contains the fix for the authentication logic, while ensuring the database is not exposed to public network access.

References