PatchSiren cyber security CVE debrief
CVE-2026-54061 dgraph-io CVE debrief
CVE-2026-54061 is a critical vulnerability in Dgraph, an open-source distributed GraphQL database. The issue allows unauthenticated network clients to access and modify database data by exploiting the external snapshot import RPCs exposed on port 9080. This can lead to data deletion and replacement. The vulnerability was patched in version 25.3.5. Organizations should prioritize patching to prevent potential data breaches. Security teams and administrators responsible for Dgraph deployments need to assess their exposure and take immediate action.
- Vendor
- dgraph-io
- Product
- dgraph
- CVSS
- CRITICAL 9.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-08
- Original CVE updated
- 2026-07-08
- Advisory published
- 2026-07-08
- Advisory updated
- 2026-07-08
Who should care
Organizations using Dgraph versions prior to 25.3.5 should prioritize patching to prevent potential data breaches. Security teams and administrators responsible for Dgraph deployments need to assess their exposure and take immediate action. Operators and platform administrators should review the vulnerability and take necessary actions to protect their systems.
Technical summary
Dgraph Alpha exposes RPCs for external snapshot import on port 9080 without authentication or authorization. An unauthenticated client can open StreamExtSnapshot and send Badger stream data, allowing data deletion and replacement by calling Prepare() before processing the stream. The vulnerability has a critical CVSS score of 9.1, indicating a high severity vulnerability. The affected product is Dgraph, and the vulnerability is patched in version 25.3.5.
Defensive priority
High priority due to critical CVSS score of 9.1 and potential for data loss and modification.
Recommended defensive actions
- Patch Dgraph to version 25.3.5 or later
- Restrict access to port 9080
- Monitor for suspicious activity
- Inventory Dgraph deployments
- Verify patch application
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record was published on 2026-07-08T14:17:06.520Z and last modified on 2026-07-08T15:28:15.630Z. The NVD entry is currently Deferred. There is limited information available about the vulnerability, and defenders should verify the affected scope and severity with the vendor. The CVE record provides a critical CVSS score of 9.1, indicating a high severity vulnerability.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-54061 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-54061
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-54061 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-54061
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/dgraph-io/dgraph/releases/tag/v25.3.5
-
Source reference
Unverified legacy reference
URL: https://github.com/dgraph-io/dgraph/security/advisories/GHSA-rrwh-6jrq-wp5v
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.