LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-40173

CVE-2026-40173 - Vulnerability Analysis

CriticalCVSS: 9.4

Last Updated: April 15, 2026

Dgraph - Broken Access Control

Published: April 15, 2026Updated: April 15, 2026Remote Exploitable

Overview

Dgraph <= 25.3.1 contains an unauthenticated credential disclosure caused by the /debug/pprof/cmdline endpoint exposing the admin token, letting attackers gain unauthorized privileged admin access, exploit requires network access to Alpha HTTP port.

Severity & Score

Severity: Critical
CVSS Score: 9.4

Impact

Attackers can gain unauthorized privileged administrative access, enabling configuration changes and operational control.

Mitigation

Upgrade to version 25.3.2 or later.

Details

CVE ID
CVE-2026-40173
Severity
Critical
CVSS Score
9.4
Type
broken_access_control
Status
new

CWE

  • CWE-200

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L