Zero Authentication, Total Control: Critical CVSS 10 Flaw Uncovered in Dgraph Database
ID: 897c63cd-d555-51e1-b5b8-56b5445629b8
STIX ID: report--897c63cd-d555-51e1-b5b8-56b5445629b8
Feed Name: securityonline.info
A critical unauthenticated remote vulnerability (CVE-2026-33976) was discovered in Dgraph's restoreTenant admin mutation (affecting all versions up to and including v25.3.0). Because the function was omitted from the admin authorization middleware, attackers can invoke it without credentials via the admin endpoint to overwrite databases, read local files using file:// URLs, perform SSRF to internal services, and access encryption keys or Vault credential files; Dgraph released a patch in v25.3.1 and administrators are urged to upgrade immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
