cvedb.io
CVE-2026-10584
MEDIUM · CVSS 5.9
EPSS exploitation probability: 0%
Published 2026-06-02T20:16:31.757 · Last modified 2026-06-17T10:12:25.033

Summary

Proxy server in Graph Explorer before 3.0.1 falls back to HTTP when certificate files are missing, which might allow remote threat actors to obtain sensitive information via interception of requests intended to be sent over HTTPS. To remediate this issue, users should upgrade to Graph Explorer v3.0.1 or later.

Does this affect you?

Add your gear to cvedb and we'll alert you only when a vendor you run ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.