CVE-2026-44840 is a DQL injection vulnerability in Dgraph’s GraphQL checkUserPassword query. The issue arises because the unauthenticated checkUserPassword code path unsafely interpolates the supplied password value into a DQL checkpwd() query string rather than safely parameterizing or correctly escaping it. An attacker can supply crafted input containing quotes and additional DQL syntax to break out of the intended password context and inject arbitrary DQL query blocks. The vulnerable condition affects deployments exposing the GraphQL endpoint that provides checkUserPassword, particularly where the @secret directive is enabled.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This eight-file Docker laboratory is an operational Python proof of concept for CVE-2026-44840, a Dgraph GraphQL-to-DQL injection condition attributed to unparameterized password interpolation in the generated checkUserPassword resolver. The primary exploit, exploit/exploit.py, sends GraphQL requests containing a variable-bound password whose value breaks out of the downstream DQL checkpwd(...) string. It injects root DQL blocks that query User fields and uses extensions.touched_uids as an execution and blind-enumeration oracle. It targets a vulnerable Dgraph v25.3.3 instance and compares results against v25.3.4. docker-compose.yml provisions isolated vulnerable and patched Zero/Alpha pairs; setup/setup.py installs the @secret User schema and test users; run.sh orchestrates the environment; and show_dql.py retrieves Docker logs to demonstrate that the rewritten DQL included the injected block. No OS command-execution, reverse-shell, credential-theft, or persistence payload is present; the demonstrated effect is arbitrary server-side DQL execution with data reconnaissance and documented denial-of-service potential.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.