CVE-2026-88410
7.1 HIGHpublic exploit availablePublished 2026-09-21 · Updated 2026-09-21
AI risk analysis
- Summary
- The flaw in FalkorDB's graph.UDF module allows unauthorized read operations, but no write commands are registered, leading to potential data exposure and integrity issues.
- Exploitability
- Exploitation requires access to the Redis instance and knowledge of the UDF usage patterns; it is moderately difficult.
- Blast radius
- If exploited, this could lead to sensitive data leakage within the application, impacting user privacy and system integrity.
- Prioritized remediation
- Update FalkorDB to version v4.20.5 or later which addresses this issue.
data-exposureredisudf
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
The graph.UDF in FalkorDB (Redis module) v4.20.1 to v4.20.4 is not registered as a write command, leading to unexpected behavior within the application.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
Public exploit & PoC references
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- MEDIUMCVE-2026-14194
- CRITICALCVE-2026-15721
- CRITICALCVE-2026-15958
- MEDIUMCVE-2026-48974PoC
- HIGHCVE-2026-55739PoC
- MEDIUMCVE-2026-58504PoC
- MEDIUMCVE-2026-59816PoC
- HIGHCVE-2026-6079
Related by shared AI tags and CWE weakness class. Browse the full archive.