Critical Dgraph Database Flaw Allowed Attackers to Bypass Authentication
ID: 78c14185-a481-5b03-bdfc-730f68a386ed
STIX ID: report--78c14185-a481-5b03-bdfc-730f68a386ed
Feed Name: GBHackers
A critical unauthenticated authorization bypass (CVE-2026-34976, CVSS 10.0) in Dgraph versions up to v25.3.0 allows remote attackers to exploit an unprotected restoreTenant command to overwrite databases with attacker-controlled backups, read sensitive server files, perform SSRF against internal services, and exfiltrate credentials; no official patch is yet available, so administrators are urged to restrict admin endpoint access, enforce strict firewall rules, or apply source-level mitigations until a fixed release is published.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
