CVE Explorer
CVE-2026-34976
Dgraph is an open source distributed GraphQL database. Prior to 25.3.1, the restoreTenant admin mutation is missing from the authorization middleware config (admin.go), making it completely unauthenticated. Unlike the similar restore mutation which requires Guardian-of-Galaxy authentication, restoreTenant executes with zero middleware. This mutation accepts attacker-controlled backup source URLs (including file:// for local filesystem access), S3/MinIO credentials, encryption key file paths, and
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"dgraph","vendor":"dgraph-io","versions":[{"status":"affected","version":"< 25.3.1"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:f31a4bfb163ed20fbec98165428d4c81cfde46b0a0f9a0aafb0c52a274278247 · sha256:263db09591760b4f… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":10,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:f31a4bfb163ed20fbec98165428d4c81cfde46b0a0f9a0aafb0c52a274278247 · sha256:263db09591760b4f… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-862","description":"CWE-862: Missing Authorization","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:f31a4bfb163ed20fbec98165428d4c81cfde46b0a0f9a0aafb0c52a274278247 · sha256:263db09591760b4f… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"tags":["exploit"],"url":"https://github.com/dgraph-io/dgraph/security/advisories/GHSA-p5rh-vmhp-gvcw"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f31a4bfb163ed20fbec98165428d4c81cfde46b0a0f9a0aafb0c52a274278247 · sha256:263db09591760b4f… · /containers/adp/0/references/0
{"name":"https://github.com/dgraph-io/dgraph/security/advisories/GHSA-p5rh-vmhp-gvcw","tags":["x_refsource_CONFIRM"],"url":"https://github.com/dgraph-io/dgraph/security/advisories/GHSA-p5rh-vmhp-gvcw"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f31a4bfb163ed20fbec98165428d4c81cfde46b0a0f9a0aafb0c52a274278247 · sha256:263db09591760b4f… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.