Summary
CVE-2026-81032 is a critical vulnerability in NebulaGraph, a distributed open-source graph database, caused by an unauthenticated HTTP web service that exposes and allows modification of daemon runtime configuration (gflags). The flaw allows any network-reachable attacker to read sensitive configuration data and dynamically alter daemon security behavior, including disabling transport security, with no authentication or user interaction required.
Technical details
- Root cause: Each NebulaGraph daemon starts an HTTP web service (defined in
WebService.cpp) that binds to all network interfaces by default and registers routes for reading and writing runtime gflags, status, and statistics — without any authentication, token validation, or address restriction. - Trigger conditions: The service is reachable by default on port 11000 without any special configuration; no credentials or prior access are required.
- Attack vector: Network (AV:N); an attacker only needs connectivity to the exposed HTTP port to send GET/PUT requests to the flags endpoint.
- Impact — read: The
GET /flagsroute returns the daemon’s full runtime configuration, including TLS certificate/key/CA paths, the password file path, data directory locations, and transport-security enable flags. - Impact — write: The
PUT /flagsroute parses a supplied key-value map and applies each entry via the gflags runtime setter, letting an attacker disable transport-security flags, redirect logs, and alter authentication-related flags such asfailed_login_attemptsandpassword_lock_time_in_secswithout restarting the daemon.
Affected software
- NebulaGraph (vesoft-inc/nebula), versions 0 through 3.8.0
Severity
- CVSS 3.1 Base Score: 9.8 (Critical) —
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS 4.0 Base Score: 9.3 (Critical) —
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Mitigation and recommended actions
- Immediate: No official patched release has been published by the vendor at this time; monitor the vesoft-inc/nebula repository for a fix.
- Workarounds: Change the web service bind address from
0.0.0.0to127.0.0.1so it is not reachable over the network; restrict access to the web service port (default 11000, and equivalents on other daemons) to trusted hosts via firewall/network segmentation; place the service behind a reverse proxy that enforces authentication (e.g., shared token, mutual TLS, or Basic auth) before allowing access to/flagsendpoints.
How IONIX identifies potentially affected assets
IONIX matches the following signals against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Page title:
NebulaGraph Studio,Nebula Graph Studio

