OVERVIEW CVE-2026-40173 affects Dgraph, an open-source distributed GraphQL database, in versions 25.3.1 and earlier. The vulnerability stems from an unauthenticated endpoint (/debug/pprof/cmdline) being accessible on the default multiplexer without requiring authentication, which exposes the full process command line including admin tokens configured during startup. This credential disclosure directly enables unauthorized privileged access to admin-only endpoints, allowing attackers to bypass authentication and gain administrative control over the database. SEVERITY This is a critical vulnerability with a CVSS score of 9.4. The attack requires no authentication, no special user interaction, and can be executed over the network with minimal complexity. An attacker can retrieve the leaked admin token from the exposed endpoint and use it in subsequent requests to access restricted administrative functions such as configuration management and operational controls. The impact is high for both confidentiality and integrity, with some availability risk, particularly severe in any deployment where the Alpha HTTP port is exposed to untrusted networks. EXPLOITATION STATUS There is no evidence of active exploitation in the wild, as indicated by the vulnerability's inactive status on exploit tracking systems and absence from CISA's Known Exploited Vulnerabilities catalog. However, the straightforward nature of the attack—simple HTTP requests to an unauthenticated endpoint—means exploit code would be trivial to develop. Organizations running Dgraph 25.3.1 or earlier should prioritize upgrading to version 25.3.2 and restrict network access to the Alpha HTTP port until patching is completed.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 25.3.2CPE matchmatch criteria | cpe:2.3:a:dgraph:dgraph:*:*:*:*:*:go:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.