Known CVE
Dgraph <= 25.3.2 - Admin Token Disclosure
Dgraph <= 25.3.2 contains an information disclosure caused by unauthenticated access to the /debug/vars endpoint , which publishes the cmdline variable including the --security token= flag, letting unauthenticated remote attackers retrieve the admin token and access admin-only endpoints, exploit requires no authentication.
CVE-2026-41492
Critical2026CVSS 9.8CWE-200
cve2026 · dgraph · exposure · token
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website