CVE-2026-41492

CRITICAL NUCLEI

Unauthenticated Admin Token Disclosure Leading to Authentication Bypass via /debug/vars in Dgraph

Title source: cna
STIX 2.1

Exploitation Summary

CVE-2026-41492 has a Nuclei detection template available — see the Nuclei card below for the Shodan/FOFA recon queries.

Description

Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, Dgraphl exposes the process command line through the unauthenticated /debug/vars endpoint on Alpha. Because the admin token is commonly supplied via the --security "token=..." startup flag, an unauthenticated attacker can retrieve that token and replay it in the X-Dgraph-AuthToken header to access admin-only endpoints. This is a variant of the previously fixed /debug/pprof/cmdline issue, but the current fix is incomplete because it blocks only /debug/pprof/cmdline and still serves http.DefaultServeMux, which includes expvar's /debug/vars handler. This vulnerability is fixed in 25.3.3.

Nuclei Templates (1)

Dgraph <= 25.3.2 - Admin Token Disclosure
CRITICALVERIFIEDby Divine Balija
Shodan: Dgraph

References (2)

Core 2
Core References

Scores

CVSS v3 9.8
EPSS 0.2699
EPSS Percentile 96.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-200
Status published
Products (4)
dgraph/dgraph < 25.3.3
dgraph-io/dgraph 0 (2 CPE variants)Go
dgraph-io/dgraph 0 - 25.3.3Go
dgraph-io/dgraph < 25.3.3
Published Apr 24, 2026
Tracked Since Apr 24, 2026