Vendor
high
advisory
CVE-2026-101066 Path Traversal in Dbgate
1 rule 2 TTPs 1 CVEDbgate versions up to 7.3.1 contain a path traversal vulnerability in the archive link creation component, allowing remote unauthenticated attackers to access arbitrary files on the filesystem via the linkedFolder parameter.
dbgate +1
1r
2t
1c
critical
advisory
DbGate Unauthenticated Remote Code Execution via JSON Script Runner (CVE-2026-47668)
2 rules 1 TTPCVE-2026-47668 is a critical remote code execution vulnerability affecting DbGate versions 7.1.8 and earlier in the JSON Script Runner component where user-controlled fields are concatenated into dynamically generated JavaScript without adequate validation, allowing arbitrary code execution, and an attacker may obtain a Bearer token and reach the vulnerable endpoint without valid credentials leading to full server compromise; upgrade to DbGate 7.1.9+ immediately to remediate the vulnerability.
dbgate-serve
cve-2026-47668
rce
dbgate
2r
1t