๐Ÿ” CVE Alert

CVE-2026-108710

MEDIUM 6.5

NornicDB through 1.4.1 Missing Authorization via Vector Search Endpoints

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

NornicDB through 1.4.1 contains a missing authorization vulnerability that allows authenticated users to bypass per-database read restrictions on the /nornicdb/search and /nornicdb/similar endpoints. Viewer-role users allowlisted for a database but denied read can submit search queries or node IDs to retrieve node IDs, labels and full property maps.

CWE CWE-862
Vendor orneryd
Product nornicdb
Published Oct 11, 2026
Stay Ahead of the Next One

Get instant alerts for orneryd nornicdb

Be the first to know when new medium vulnerabilities affecting orneryd nornicdb are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

orneryd / NornicDB
0 โ‰ค 1.4.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
hackmd.io: https://hackmd.io/@haind/orneryd-nornicdb-vector-endpoints-per-db-read-bypass github.com: https://github.com/orneryd/NornicDB/blob/67105489e6da00714b998faf9012ffa44f526245/pkg/server/server_nornicdb.go#L415-L419 github.com: https://github.com/orneryd/NornicDB/blob/67105489e6da00714b998faf9012ffa44f526245/pkg/server/server_nornicdb.go#L811-L815 github.com: https://github.com/orneryd/NornicDB/blob/67105489e6da00714b998faf9012ffa44f526245/pkg/server/server_graph.go#L418-L423 github.com: https://github.com/orneryd/NornicDB vulncheck.com: https://www.vulncheck.com/advisories/nornicdb-through-1.4.1-missing-authorization-via-vector-search-endpoints

Credits

HaiND from the Post and Telecommunication Institute of Technology