Signal is active with 1 mentions in latest observed window
Immediate actions
Patch affected systems immediately
Recommended action window: Monitor and triage in normal cycle
NVD description
Dgraph is an open source distributed GraphQL database. Prior to version 25.3.5, Dgraph Alpha exposes the RPCs used for external snapshot import on the public gRPC port `:9080` without authentication or authorization. As a result, an unauthenticated network client can open `StreamExtSnapshot` and send Badger stream data to the target group’s store. In addition, the receiver calls `Prepare()` before processing the stream. This operation deletes and replaces the existing DB data. Version 25.3.5 patches the issue.
Peaked 1d ago at 1 mentions (2026-07-08); latest day: 1
2 total mentions across 2 days
Deep dive
>Activity timeline2 mentions / 2d
>Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
>Classification over time
Date
Total
Labels
2026-07-08
1
Disclosure1
2026-07-10
1
Patch1
>Full discourse2 posts
DFIR Lab@DFIR_Lab·
Patch
🚨 CRITICAL: CVE-2026-54061 (CVSS 9.1)
Dgraph database exposes unauthenticated RPCs on port 9080, allowing attackers to delete/replace DB data remotely.
Patch to v25.3.5 immediately.
#CVE#PatchNow https://t.co/8TpoFvcp4l
Post summary
The tweet alerts that Dgraph’s unauthenticated RPCs enable remote data deletion, and it urges users to apply the v25.3.5 patch immediately.
🚨 CRITICAL - Unauthenticated external snapshot import wipes Dgraph data (CVE-2026-54061)
Dgraph Alpha exposed privileged RPCs for external snapshot import on its public gRPC port :9080, specifically via the StreamExtSnapshot endpoint in affected versions. The root cause is missing authentication/authorization (improper access control) on a dangerous administrative gRPC method combined with unsafe import workflow ordering. An unauthenticated remote client can connect over the network to :9080 and stream crafted Badger snapshot data, triggering Prepare() before validation which deletes and replaces existing database contents. Successful exploitation results in full database destruction/replacement leading to severe data loss, service outage, and potential integrity compromise.
👉 Affected: dgraph (prior to 25.3.5) | Upgrade to 25.3.5
Post summary
A critical CVE-2026-54061 in Dgraph permits unauthenticated remote clients to fully wipe the database via external snapshot import; upgrading to 25.3.5 resolves the vulnerability.