CVE-2026-42072: CWE-1392: Use of Default Credentials in orneryd NornicDB
Nornicdb is a distributed low-latency, Graph+Vector, Temporal MVCC with all sub-ms HNSW search, graph traversal, and writes. Prior to version 1.0.42-hotfix, the --address CLI flag (and NORNICDB_ADDRESS / server.host config key) is plumbed through to the HTTP server correctly but never reaches the Bolt server config. The Bolt listener therefore always binds to the wildcard address (all interfaces), regardless of what the user configures. On a LAN, this exposes the graph database — with its default admin:password credentials — to any device sharing the network. This issue has been patched in version 1.0.42-hotfix.
AI Analysis
Technical Summary
NornicDB, a distributed graph and vector database, improperly handles the --address CLI flag and related configuration keys for the Bolt server listener in versions before 1.0.42-hotfix. Although the HTTP server respects the configured address, the Bolt server always binds to the wildcard address (all interfaces). Consequently, on a local area network, the database is exposed with default credentials (admin:password), creating a critical security risk. This vulnerability is tracked as CVE-2026-42072 with a CVSS score of 9.8 and has been patched in version 1.0.42-hotfix.
Potential Impact
The vulnerability allows an attacker on the same LAN to connect to the Bolt server interface of NornicDB using default credentials, potentially leading to full compromise of confidentiality, integrity, and availability of the database. The CVSS score of 9.8 reflects critical impact with network attack vector, no required privileges or user interaction, and full system compromise possible.
Mitigation Recommendations
Upgrade NornicDB to version 1.0.42-hotfix or later, where the Bolt server listener correctly respects the configured address and does not bind to all interfaces by default. This patch effectively mitigates the exposure of the database with default credentials on the network. Until upgraded, restrict network access to the Bolt server interface to trusted hosts only.
CVE-2026-42072: CWE-1392: Use of Default Credentials in orneryd NornicDB
Description
Nornicdb is a distributed low-latency, Graph+Vector, Temporal MVCC with all sub-ms HNSW search, graph traversal, and writes. Prior to version 1.0.42-hotfix, the --address CLI flag (and NORNICDB_ADDRESS / server.host config key) is plumbed through to the HTTP server correctly but never reaches the Bolt server config. The Bolt listener therefore always binds to the wildcard address (all interfaces), regardless of what the user configures. On a LAN, this exposes the graph database — with its default admin:password credentials — to any device sharing the network. This issue has been patched in version 1.0.42-hotfix.
CVSS v3.1
Score 9.8critical
Affected software
pkg:github/orneryd/NornicDBRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
NornicDB, a distributed graph and vector database, improperly handles the --address CLI flag and related configuration keys for the Bolt server listener in versions before 1.0.42-hotfix. Although the HTTP server respects the configured address, the Bolt server always binds to the wildcard address (all interfaces). Consequently, on a local area network, the database is exposed with default credentials (admin:password), creating a critical security risk. This vulnerability is tracked as CVE-2026-42072 with a CVSS score of 9.8 and has been patched in version 1.0.42-hotfix.
Potential Impact
The vulnerability allows an attacker on the same LAN to connect to the Bolt server interface of NornicDB using default credentials, potentially leading to full compromise of confidentiality, integrity, and availability of the database. The CVSS score of 9.8 reflects critical impact with network attack vector, no required privileges or user interaction, and full system compromise possible.
Mitigation Recommendations
Upgrade NornicDB to version 1.0.42-hotfix or later, where the Bolt server listener correctly respects the configured address and does not bind to all interfaces by default. This patch effectively mitigates the exposure of the database with default credentials on the network. Until upgraded, restrict network access to the Bolt server interface to trusted hosts only.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-04-23T19:17:30.565Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 69fe0d85cbff5d8610fb9964
Added to database: 05/08/2026, 16:21:25 UTC
Last enriched: 05/16/2026, 10:16:32 UTC
Last updated: 07/31/2026, 19:22:58 UTC
Views: 178
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.