DbGate is cross-platform database manager. Versions 7.1.8 and prior are vulnerable to authenticated Remote Code Execution (RCE). Any user with valid DbGate credentials can execute arbitrary OS commands as root by exploiting an unsanitized `functionName` parameter in the `/runners/load-reader` endpoint. The `require = null` mitigation is trivially bypassed via dynamic `import()`. Version 7.1.9 contains a patch.
CVSS
No CVSS.
References
Configurations
No configuration.
History
23 Jul 2026, 20:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-23 20:17
Updated : 2026-07-28 16:17
NVD link : CVE-2026-47670
Mitre link : CVE-2026-47670
CVE.ORG link : CVE-2026-47670
JSON object : View
Products Affected
No product.
