CVE-2026-107910 PUBLISHED

Authentication bypass in FalkorDB Bolt endpoint via fail-open AUTH probe error handling

Assigner: securin
Reserved: 09.10.2026 Published: 09.10.2026 Updated: 09.10.2026

An improper authentication vulnerability in the is_authenticated function (src/bolt/bolt_api.c) in FalkorDB before 4.20.0 allows a remote unauthenticated attacker to execute graph queries without credentials through the Bolt endpoint. The function decides whether a password is required by issuing an empty AUTH command to Redis and treats only a WRONGPASS error as meaning that a password is required; any other error, such as LOADING while a dataset is being loaded, MASTERDOWN during replication failover, or OOM under memory pressure, causes the client to be treated as authenticated. Only deployments that enable the Bolt endpoint (BOLT_PORT, disabled by default) are affected.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.2

Product Status

Vendor FalkorDB
Product FalkorDB
Versions Default: unaffected
  • affected from 0 to 4.20.0 (excl.)

Workarounds

Leave the Bolt endpoint disabled (do not set the BOLT_PORT module configuration; it is disabled by default), or restrict network access to the Bolt port to trusted clients.

Solutions

Upgrade FalkorDB to version 4.20.0 or later. Bolt protocol support, including the code affected by this issue, was removed in 4.20.0.

Credits

  • Arjun Basnet from Securin finder

References

Problem Types

  • CWE-287 Improper Authentication CWE

Impacts

  • CAPEC-115 Authentication Bypass