<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Dbgate (Up to 6.8.1, 7.0.2, 7.1.8, 7.2.5, 7.3.1) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/dbgate-up-to-6.8.1-7.0.2-7.1.8-7.2.5-7.3.1/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 28 Sep 2026 14:14:49 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/dbgate-up-to-6.8.1-7.0.2-7.1.8-7.2.5-7.3.1/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>CVE-2026-101066 Path Traversal in Dbgate</title><link>https://feed.craftedsignal.io/briefs/2026-09-dbgate-path-traversal/</link><pubDate>Mon, 28 Sep 2026 14:14:49 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-dbgate-path-traversal/</guid><description>Dbgate versions up to 7.3.1 contain a path traversal vulnerability in the archive link creation component, allowing remote unauthenticated attackers to access arbitrary files on the filesystem via the linkedFolder parameter.</description><content:encoded><![CDATA[<p>Dbgate versions up to 7.3.1 are vulnerable to a path traversal vulnerability identified as CVE-2026-101066. The issue exists within the createLink function located in packages/api/src/controllers/archive.js. An attacker can manipulate the linkedFolder argument to break out of the intended directory structure and access sensitive files on the host server. This vulnerability is remotely exploitable without authentication and is currently subject to public disclosure with no available vendor patch. Given the nature of Dbgate as a database management tool, successful exploitation could lead to the exposure of database configuration files, credentials, and other sensitive system information stored on the host running the application.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows remote attackers to read unauthorized files from the filesystem where Dbgate is installed. This can lead to full system compromise if configuration files containing database credentials are exfiltrated. The vulnerability affects all deployments of Dbgate versions 7.3.1 and earlier, regardless of the underlying operating system.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for security teams:</p>
<ul>
<li>Identify all instances of Dbgate deployed within the environment and audit their exposure to the internet.</li>
<li>Apply network-level access control lists (ACLs) to restrict access to Dbgate interfaces to trusted management subnets until a patch is released.</li>
<li>Monitor web server access logs for requests containing directory traversal patterns such as &quot;../&quot; in the linkedFolder parameter targeting the archive controller.</li>
<li>Implement file integrity monitoring (FIM) on critical application configuration files to detect unauthorized access attempts.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>