NornicDB through 1.4.1 contains a missing authorization vulnerability that allows authenticated users to bypass per-database read restrictions on the /nornicdb/search and /nornicdb/similar endpoints. Viewer-role users allowlisted for a database but denied read can submit search queries or node IDs to retrieve node IDs, labels and full property maps.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 11 Oct 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Orneryd
Orneryd nornicdb |
|
| Vendors & Products |
Orneryd
Orneryd nornicdb |
Sun, 11 Oct 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NornicDB through 1.4.1 contains a missing authorization vulnerability that allows authenticated users to bypass per-database read restrictions on the /nornicdb/search and /nornicdb/similar endpoints. Viewer-role users allowlisted for a database but denied read can submit search queries or node IDs to retrieve node IDs, labels and full property maps. | |
| Title | NornicDB through 1.4.1 Missing Authorization via Vector Search Endpoints | |
| Weaknesses | CWE-862 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-11T12:19:24.730Z
Reserved: 2026-10-11T01:51:06.146Z
Link: CVE-2026-108710
No data.
Status : Received
Published: 2026-10-11T13:17:13.720
Modified: 2026-10-11T13:17:13.720
Link: CVE-2026-108710
No data.
OpenCVE Enrichment
Updated: 2026-10-11T13:30:18Z
Weaknesses