Skip to content
dgraphGO-2026-6261

Dgraph Alpha group stores can be replaced via unauthenticated external snapshot import in github.com/dgraph-io/dgraph

Critical9.1CVE-2026-54061 · Published Aug 25, 2026 · updated Aug 26, 2026

Source advisory

Affected versions

PackageAffectedFixed in
github.com/dgraph-io/dgraph
Go
all versionsNo fix yet

Changes since it was listed

DateChange
Sep 25Severity: Unrated to Critical
Details and references

Dgraph Alpha exposes the RPCs used for external snapshot import on the public gRPC port without authentication or authorization. An unauthenticated network client can call StreamExtSnapshot and send Badger stream data to replace a target group's store, which drops and replaces the existing database data.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Severity from
NVD
Also known as
CVE-2026-54061, GHSA-rrwh-6jrq-wp5v

More dgraph advisories

All
DateAdvisory
Jul 7DQL injection via checkUserPassword GraphQL query in github.com/dgraph-io/dgraph
CVE-2026-44840High7.5no fix yet
Apr 24Dgraph: Unauthenticated Admin Token Disclosure Leading to Authentication Bypass via /debug/vars
CVE-2026-41492Critical9.8no fix yet
Apr 24Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in NQuad Lang Field
CVE-2026-41328Critical9.1no fix yet
Apr 24Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in Upsert Condition Field
CVE-2026-41327Critical9.1no fix yet
Apr 16Dgraph: Unauthenticated /debug/pprof/cmdline discloses admin auth token, enabling unauthorized access to protected Alpha admin endpoints
CVE-2026-40173Critical9.4no fix yet
Apr 2Dgraph: Pre-Auth Database Overwrite + SSRF + File Read via restoreTenant Missing Authorization
CVE-2026-34976Critical10.0no fix yet

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.