VYPR

NornicDB

by Orneryd

CVEs (1)

  • CVE-2026-108710MedOct 11, 2026
    risk 0.42cvss 6.5epss —

    NornicDB through 1.4.1 contains a missing authorization vulnerability that allows authenticated users to bypass per-database read restrictions on the /nornicdb/search and /nornicdb/similar endpoints. Viewer-role users allowlisted for a database but denied read can submit search…