


Perceptive Security
SOC/SIEM Consultancy

Dgraph is an open source distributed GraphQL database. Prior to version 25.3.5, Dgraph Alpha exposes the RPCs used for external snapshot import on the public gR…
Published:
7 juli 2026 om 22:00:00
Alert date:
8 juli 2026 om 15:06:43
Source:
nvd.nist.gov
Database & Storage, Identity & Access, Web Technologies
CVE-2026-54061 affects Dgraph, an open source distributed GraphQL database. Prior to version 25.3.5, Dgraph Alpha exposes snapshot import RPCs on the public gRPC port 9080 without any authentication or authorization controls. An unauthenticated remote attacker can exploit this by calling StreamExtSnapshot to send arbitrary Badger stream data to the target group's data store. Before processing the stream, the receiver invokes Prepare(), which deletes and replaces all existing database data, enabling complete data destruction or replacement. This represents a critical data integrity and availability risk for any exposed Dgraph instance. The vulnerability has been patched in version 25.3.5. Users are strongly advised to upgrade immediately to mitigate the risk of unauthorized data manipulation or destruction.
Technical details
Mitigation steps:
Affected products:
Dgraph
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-54061
https://github.com/dgraph-io/dgraph/releases/tag/v25.3.5
https://github.com/dgraph-io/dgraph/security/advisories/GHSA-rrwh-6jrq-wp5v
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
