All verified exploits

CVE-2026-34976 Unauthenticated Database Overwrite via restoreTenant Mutation

Deterministic critical Dgraph Added cve-verified-cve-2026-34976

Detects Dgraph instances before v25.3.1 / v24.1.6 where the restoreTenant admin GraphQL mutation is missing from the authorization middleware configuration. An unauthenticated attacker can overwrite the entire database from a malicious backup, read server files via file:// URIs, or reach internal services via SSRF. The fix adds restoreTenant to the Guardian-of-the-Galaxy middleware map.

Is your app exploitable through CVE-2026-34976?

Scan your domain free