dgraphGO-2026-6261
Dgraph Alpha group stores can be replaced via unauthenticated external snapshot import in github.com/dgraph-io/dgraph
Critical9.1CVE-2026-54061 · Published Aug 25, 2026 · updated Aug 26, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/dgraph-io/dgraph Go | all versions | No fix yet |
Changes since it was listed
| Date | Change |
|---|---|
| Sep 25 | Severity: Unrated to Critical |
Details and references
Dgraph Alpha exposes the RPCs used for external snapshot import on the public gRPC port without authentication or authorization. An unauthenticated network client can call StreamExtSnapshot and send Badger stream data to replace a target group's store, which drops and replaces the existing database data.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
- Severity from
- NVD
- Also known as
- CVE-2026-54061, GHSA-rrwh-6jrq-wp5v
More dgraph advisories
All| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 7 | DQL injection via checkUserPassword GraphQL query in github.com/dgraph-io/dgraph CVE-2026-44840High7.5no fix yet | High7.5 | No fix yet |
| Apr 24 | Dgraph: Unauthenticated Admin Token Disclosure Leading to Authentication Bypass via /debug/vars CVE-2026-41492Critical9.8no fix yet | Critical9.8 | No fix yet |
| Apr 24 | Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in NQuad Lang Field CVE-2026-41328Critical9.1no fix yet | Critical9.1 | No fix yet |
| Apr 24 | Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in Upsert Condition Field CVE-2026-41327Critical9.1no fix yet | Critical9.1 | No fix yet |
| Apr 16 | Dgraph: Unauthenticated /debug/pprof/cmdline discloses admin auth token, enabling unauthorized access to protected Alpha admin endpoints CVE-2026-40173Critical9.4no fix yet | Critical9.4 | No fix yet |
| Apr 2 | Dgraph: Pre-Auth Database Overwrite + SSRF + File Read via restoreTenant Missing Authorization CVE-2026-34976Critical10.0no fix yet | Critical10.0 | No fix yet |