Skip to content

Known CVE

Dgraph <= 25.3.2 - Admin Token Disclosure

Dgraph <= 25.3.2 contains an information disclosure caused by unauthenticated access to the /debug/vars endpoint , which publishes the cmdline variable including the --security token= flag, letting unauthenticated remote attackers retrieve the admin token and access admin-only endpoints, exploit requires no authentication.

CVE-2026-41492

Critical2026CVSS 9.8CWE-200

cve2026 · dgraph · exposure · token

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website