Critical Dgraph Database Vulnerability Let Attackers Bypass Authentication
ID: 60c65cfd-4665-5e46-b88b-b082334d7d29
STIX ID: report--60c65cfd-4665-5e46-b88b-b082334d7d29
Feed Name: cybersecurityNews.com
A maximum-severity (CVSS 10.0) vulnerability in Dgraph’s GraphQL administration API (CVE-2026-34976) allows unauthenticated attackers to bypass all security controls because the restoreTenant mutation was omitted from the administrative middleware; attackers can restore attacker-controlled backups to overwrite databases, probe local files via file:// URIs, and trigger SSRF to reach internal services or metadata endpoints. The issue affects Dgraph versions 25.3.0 and older, had no official patch at disclosure, and the recommended mitigations are to immediately isolate administration ports (typically 8080), restrict access to trusted IPs, and monitor upstream fixes on GitHub.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
