Detects Dgraph instances before v25.3.1 / v24.1.6 where the restoreTenant admin GraphQL mutation is missing from the authorization middleware configuration. An unauthenticated attacker can overwrite the entire database from a malicious backup, read server files via file:// URIs, or reach internal services via SSRF. The fix adds restoreTenant to the Guardian-of-the-Galaxy middleware map.
Is your app exploitable through CVE-2026-34976?
Scan your domain free