CVE-2026-47670

DbGate is cross-platform database manager. Versions 7.1.8 and prior are vulnerable to authenticated Remote Code Execution (RCE). Any user with valid DbGate credentials can execute arbitrary OS commands as root by exploiting an unsanitized `functionName` parameter in the `/runners/load-reader` endpoint. The `require = null` mitigation is trivially bypassed via dynamic `import()`. Version 7.1.9 contains a patch.
CVSS

No CVSS.

Configurations

No configuration.

History

23 Jul 2026, 20:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-23 20:17

Updated : 2026-07-28 16:17


NVD link : CVE-2026-47670

Mitre link : CVE-2026-47670

CVE.ORG link : CVE-2026-47670


JSON object : View

Products Affected

No product.

CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')