PT-2026-76027 · Go · Github.Com/Dgraph-Io/Dgraph+2
Published
2026-08-11
·
Updated
2026-08-11
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
The restoreTenant GraphQL mutation in Dgraph was missing from the admin mutation middleware configuration. This omission bypassed all authentication, IP whitelisting, and audit logging for this mutation.
An unauthenticated remote attacker could use this mutation to trigger a database restore from an arbitrary URL, potentially leading to a complete database overwrite, Server-Side Request Forgery (SSRF), or arbitrary file read on the host system.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Github.Com/Dgraph-Io/Dgraph
Github.Com/Dgraph-Io/Dgraph/V25
Github.Com/Hypermodeinc/Dgraph/V24