PT-2026-76027 · Go · Github.Com/Dgraph-Io/Dgraph+2

Published

2026-08-11

·

Updated

2026-08-11

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
The restoreTenant GraphQL mutation in Dgraph was missing from the admin mutation middleware configuration. This omission bypassed all authentication, IP whitelisting, and audit logging for this mutation.
An unauthenticated remote attacker could use this mutation to trigger a database restore from an arbitrary URL, potentially leading to a complete database overwrite, Server-Side Request Forgery (SSRF), or arbitrary file read on the host system.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

GO-2026-5529

Affected Products

Github.Com/Dgraph-Io/Dgraph
Github.Com/Dgraph-Io/Dgraph/V25
Github.Com/Hypermodeinc/Dgraph/V24