DbGate Vulnerable to Authenticated Remote Code Execution via loadReader functionName code injection
63Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendcvss 9.4epss 1.7%
from disclosure to weapon0 days
Published on NVDJul 23
1st PoCJun 18
exploitation probability
1.7%top 25% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
DbGate is cross-platform database manager. Versions 7.1.8 and prior are vulnerable to authenticated Remote Code Execution (RCE). Any user with valid DbGate credentials can execute arbitrary OS commands as root by exploiting an unsanitized `functionName` parameter in the `/runners/load-reader` endpoint. The `require = null` mitigation is trivially bypassed via dynamic `import()`. Version 7.1.9 contains a patch.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Affected products
dbgate · dbgatepublic PoCs found — 1
githubgithub.com/error-inside/CVE-2026-47670★ 0⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.