๐Ÿ” CVE Alert

CVE-2026-47670

UNKNOWN 0.0

DbGate Vulnerable to Authenticated Remote Code Execution via loadReader functionName code injection

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

DbGate is cross-platform database manager. Versions 7.1.8 and prior are vulnerable to authenticated Remote Code Execution (RCE). Any user with valid DbGate credentials can execute arbitrary OS commands as root by exploiting an unsanitized `functionName` parameter in the `/runners/load-reader` endpoint. The `require = null` mitigation is trivially bypassed via dynamic `import()`. Version 7.1.9 contains a patch.

CWE CWE-77 CWE-78
Vendor dbgate
Product dbgate
Published Jul 23, 2026
Stay Ahead of the Next One

Get instant alerts for dbgate dbgate

Be the first to know when new unknown vulnerabilities affecting dbgate dbgate are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

dbgate / dbgate
< 7.1.9

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/dbgate/dbgate/security/advisories/GHSA-wm5r-5qp3-5vxf github.com: https://github.com/dbgate/dbgate/releases/tag/v7.1.9