Live Exposure Defense: From CVE to Confirmed Exposure in 12 Hours – See more

New CVE Detected

CVE-2026-81032 – Unauthenticated Runtime Configuration Disclosure & Tampering – NebulaGraph (up to 3

Be the first to know when new zero-days emerge:

Summary

CVE-2026-81032 is a critical vulnerability in NebulaGraph, a distributed open-source graph database, caused by an unauthenticated HTTP web service that exposes and allows modification of daemon runtime configuration (gflags). The flaw allows any network-reachable attacker to read sensitive configuration data and dynamically alter daemon security behavior, including disabling transport security, with no authentication or user interaction required.

Technical details

  • Root cause: Each NebulaGraph daemon starts an HTTP web service (defined in WebService.cpp) that binds to all network interfaces by default and registers routes for reading and writing runtime gflags, status, and statistics — without any authentication, token validation, or address restriction.
  • Trigger conditions: The service is reachable by default on port 11000 without any special configuration; no credentials or prior access are required.
  • Attack vector: Network (AV:N); an attacker only needs connectivity to the exposed HTTP port to send GET/PUT requests to the flags endpoint.
  • Impact — read: The GET /flags route returns the daemon’s full runtime configuration, including TLS certificate/key/CA paths, the password file path, data directory locations, and transport-security enable flags.
  • Impact — write: The PUT /flags route parses a supplied key-value map and applies each entry via the gflags runtime setter, letting an attacker disable transport-security flags, redirect logs, and alter authentication-related flags such as failed_login_attempts and password_lock_time_in_secs without restarting the daemon.

Affected software

  • NebulaGraph (vesoft-inc/nebula), versions 0 through 3.8.0

Severity

  • CVSS 3.1 Base Score: 9.8 (Critical) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • CVSS 4.0 Base Score: 9.3 (Critical) — CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Mitigation and recommended actions

  • Immediate: No official patched release has been published by the vendor at this time; monitor the vesoft-inc/nebula repository for a fix.
  • Workarounds: Change the web service bind address from 0.0.0.0 to 127.0.0.1 so it is not reachable over the network; restrict access to the web service port (default 11000, and equivalents on other daemons) to trusted hosts via firewall/network segmentation; place the service behind a reverse proxy that enforces authentication (e.g., shared token, mutual TLS, or Basic auth) before allowing access to /flags endpoints.

How IONIX identifies potentially affected assets

IONIX matches the following signals against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.

  • Page title: NebulaGraph Studio, Nebula Graph Studio

References

Are you exposed?

Get a free report of your organization’s exposure to this CVE and threat

How IONIX’s External Exposure Management Platform Detects and Validates
Zero-Days to Shrink MTTR

1

Map your entire attack surface (continously)

IONIX uses multi-factor discovery methods, including DNS analysis, certificate mapping, metadata inspection, and more, to automatically map every internet-facing asset across your environment. This includes cloud instances, third-party platforms, shadow IT, and even forgotten infrastructure that traditional tools miss.

2

Monitor for new CVEs

Dozens of threat intel feeds using agentic technology are continuously analyzed to detect the appearance of proof-of-concept code, exploit kits, and indicators of active targeting. IONIX goes further by applying AI to proactively evaluate whether emerging vulnerabilities are likely to be exploited, even before PoCs go public.

3

Identify Potential External Exposures

Not all CVEs matter. IONIX filters vulnerabilities by asking attacker-centric questions: Can it be reached from the internet? Does it require authentication? Is it being exploited in the wild? This dramatically reduces noise and focuses teams on threats that can actually be weaponized.

4

Create Safe, Scalable Exploit Validations

IONIX transforms real-world PoCs into safe, non-intrusive test payloads that can be run in production environments without disruption. These simulations are precisely targeted to the systems that are vulnerable, ensuring rapid validation without unnecessary load.

5

Execute Exploit Validations

By combining context about software stack, versioning, exposure status, and reachability, IONIX ensures that only the right payloads are executed against the right assets, maximizing efficiency and minimizing risk.

6

Drive Fast and Actionable Remediation

Results are routed through integrations with ticketing, SOAR, and SIEM tools. Issues are written in plain language, bundled into remediation clusters, and prioritized based on asset criticality, exploitability, and blast radius. This shortens mean time to remediation (MTTR) and empowers teams to act with confidence.

Are you exposed?

Get a free report of your organization’s exposure to this CVE and threat

Subscribe to Threat Center RSS

Copy/paste the link below into your preferred RSS reader or follow these instructions to subscribe to Slack alerts.

Get Real-Time CVE Alerts to Your Email

Be the first to know when new zero-days emerge