A critical vulnerability in the open-source Dgraph graph database, tracked as CVE-2026-34976, allowed unauthenticated remote attackers to access the GraphQL administration API and invoke the restoreTenant mutation without authorization. The flaw, rated CVSS 10.0, affected Dgraph 25.3.0 and earlier because restoreTenant was omitted from the authorization middleware in admin.go, unlike the related restore operation that required Guardian-of-Galaxy authentication.
By abusing restoreTenant, attackers could overwrite databases from attacker-controlled backups, read sensitive local files through file:// paths, and trigger SSRF requests to internal services, including cloud metadata endpoints. The issue also exposed paths involving S3 or MinIO backup sources, encryption keys, and Vault credentials, creating a risk of complete compromise of confidentiality, integrity, and availability. Dgraph addressed the issue in version 25.3.1, and defenders were urged to keep administration endpoints such as port 8080 off the public internet and restrict access to trusted internal IPs.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Public reporting disclosed the critical Dgraph vulnerability as CVE-2026-34976 with a CVSS score of 10.0 and warned defenders to restrict access to administration endpoints such as port 8080. One disclosure noted that, at the time of publication, no official patch had yet been released.
Dgraph addressed CVE-2026-34976 in version 25.3.1 by fixing the missing authorization protection around the restoreTenant functionality. The patched release closed the unauthenticated path that could be abused for destructive administrative actions.
A missing authorization check in Dgraph's GraphQL administration API left the restoreTenant mutation accessible without authentication in version 25.3.0 and earlier. The flaw enabled pre-auth database overwrite, server-side file reads via file:// paths, and SSRF using attacker-controlled backup sources and credentials.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.