logo

Zero Authentication, Total Control: Critical CVSS 10 Flaw Uncovered in Dgraph Database

ID: 897c63cd-d555-51e1-b5b8-56b5445629b8

STIX ID: report--897c63cd-d555-51e1-b5b8-56b5445629b8

Feed Name: securityonline.info

Threat Score
95/100

Date Published: 2026-04-05

Date Updated: 2026-04-23

Author: Ddos

...
...

A critical unauthenticated remote vulnerability (CVE-2026-33976) was discovered in Dgraph's restoreTenant admin mutation (affecting all versions up to and including v25.3.0). Because the function was omitted from the admin authorization middleware, attackers can invoke it without credentials via the admin endpoint to overwrite databases, read local files using file:// URLs, perform SSRF to internal services, and access encryption keys or Vault credential files; Dgraph released a patch in v25.3.1 and administrators are urged to upgrade immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.