CVE-2026-54061
CRITICALDgraph Alpha group stores can be replaced via unauthenticated external snapshot import
Title source: cnaDescription
Dgraph is an open source distributed GraphQL database. Prior to version 25.3.5, Dgraph Alpha exposes the RPCs used for external snapshot import on the public gRPC port `:9080` without authentication or authorization. As a result, an unauthenticated network client can open `StreamExtSnapshot` and send Badger stream data to the target group’s store. In addition, the receiver calls `Prepare()` before processing the stream. This operation deletes and replaces the existing DB data. Version 25.3.5 patches the issue.
References (2)
Core 2
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/dgraph-io/dgraph/security/advisories/GHSA-rrwh-6jrq-wp5v
X_Refsource_Misc x_refsource_misc
https://github.com/dgraph-io/dgraph/releases/tag/v25.3.5
Scores
CVSS v3
9.1
EPSS
0.0039
EPSS Percentile
31.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
total
Details
CWE
CWE-306
Status
published
Products (1)
dgraph-io/dgraph
< 25.3.5
Published
Jul 08, 2026
Tracked Since
Jul 08, 2026