CVE-2026-54061Disclosure

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Dgraph is an open source distributed GraphQL database. Prior to version 25.3.5, Dgraph Alpha exposes the RPCs used for external snapshot import on the public gRPC port `:9080` without authentication or authorization. As a result, an unauthenticated network client can open `StreamExtSnapshot` and send Badger stream data to the target group’s store. In addition, the receiver calls `Prepare()` before processing the stream. This operation deletes and replaces the existing DB data. Version 25.3.5 patches the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-07-08); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-07-08: 1Mentions · 2026-07-10: 1Patch / Workaround · 2026-07-08: 1Patch / Workaround · 2026-07-10: 1Technical Details · 2026-07-08: 1Technical Details · 2026-07-10: 107-0807-10
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Classification over time
DateTotalLabels
2026-07-081
Disclosure1
2026-07-101
Patch1
Full discourse2 posts
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 CRITICAL: CVE-2026-54061 (CVSS 9.1) Dgraph database exposes unauthenticated RPCs on port 9080, allowing attackers to delete/replace DB data remotely. Patch to v25.3.5 immediately. #CVE #PatchNow https://t.co/8TpoFvcp4l

    Post summary

    The tweet alerts that Dgraph’s unauthenticated RPCs enable remote data deletion, and it urges users to apply the v25.3.5 patch immediately.

    0000057
    71 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 CRITICAL - Unauthenticated external snapshot import wipes Dgraph data (CVE-2026-54061) Dgraph Alpha exposed privileged RPCs for external snapshot import on its public gRPC port :9080, specifically via the StreamExtSnapshot endpoint in affected versions. The root cause is missing authentication/authorization (improper access control) on a dangerous administrative gRPC method combined with unsafe import workflow ordering. An unauthenticated remote client can connect over the network to :9080 and stream crafted Badger snapshot data, triggering Prepare() before validation which deletes and replaces existing database contents. Successful exploitation results in full database destruction/replacement leading to severe data loss, service outage, and potential integrity compromise. 👉 Affected: dgraph (prior to 25.3.5) | Upgrade to 25.3.5

    Post summary

    A critical CVE-2026-54061 in Dgraph permits unauthenticated remote clients to fully wipe the database via external snapshot import; upgrading to 25.3.5 resolves the vulnerability.

    00000102
    246 followersView on X

Explore more