CVE Feed

    Dashboard / CVE / CVE-2026-47670

    CVE-2026-47670

    DbGate is cross-platform database manager. Versions 7.1.8 and prior are vulnerable to authenticated Remote Code Execution (RCE). Any user with valid DbGate credentials can execute arbitrary OS commands as root by exploiting an unsanitized `functionName` parameter in the `/runners/load-reader` endpoint. The `require = null` mitigation is trivially bypassed via dynamic `import()`. Version 7.1.9 contains a patch.

    Published:Jul 23, 2026
    Last Modified:Jul 24, 2026
    EPS:Jul 23, 2026
    EPSS Score:0.01714
    CVSS Score:9.4

    Affected Products

    Vendor
    Dbgate
    Product
    Dbgate

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High