{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3adbgatedbgate/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:dbgate:dbgate:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-85176"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["DbGate"],"_cs_severities":["high"],"_cs_tags":["web-application","path-traversal","data-exfiltration"],"_cs_type":"advisory","_cs_vendors":["DbGate"],"content_html":"\u003cp\u003eCVE-2026-85176 is a critical vulnerability affecting DbGate, specifically within the jsldata controller. The application fails to properly validate the jslid parameters, which are processed by the getJslFileName() function. An authenticated user can leverage the file:// scheme to bypass directory containment mechanisms. This flaw allows an attacker to access arbitrary files on the underlying host filesystem, including sensitive configuration files that store encrypted database credentials. Successful exploitation results in full file-read and file-write capabilities, potentially leading to total system compromise or further lateral movement by extracting stored credentials.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability poses a severe risk to organizations using DbGate, as it allows authenticated attackers to read sensitive local files and overwrite critical application or system data. This can lead to the exfiltration of sensitive connection strings and encrypted credentials. The impact is significant for environments where DbGate is used to manage multiple database connections, as it provides a pathway for an attacker to gain credentials for all managed databases.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eIdentify all instances of DbGate within the infrastructure.\u003c/li\u003e\n\u003cli\u003eMonitor web application access logs for requests targeting the /jsldata controller with file:// URI schemes in the jslid parameter.\u003c/li\u003e\n\u003cli\u003eApply patches provided by the vendor to address the improper validation in getJslFileName().\u003c/li\u003e\n\u003cli\u003eImplement strict network segmentation to restrict access to the DbGate web interface to trusted administrative IP ranges.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-03T15:21:46Z","date_published":"2026-09-03T15:21:46Z","id":"https://feed.craftedsignal.io/briefs/2026-09-dbgate-path-traversal/","summary":"Authenticated attackers can exploit a path traversal vulnerability in the DbGate jsldata controller to achieve arbitrary file read and write access.","title":"Arbitrary File Access in DbGate via jsldata Controller","url":"https://feed.craftedsignal.io/briefs/2026-09-dbgate-path-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:dbgate:dbgate:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}