CVE-2026-47670
published 2026-07-23CVE-2026-47670: DbGate is cross-platform database manager. Versions 7.1.8 and prior are vulnerable to authenticated Remote Code Execution (RCE). Any user with valid DbGate…
PriorityP275critical9.4CVSS 4.0
AVNACLATNPRLUINVCHVIHVAHSCHSIHSAHEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EXPLOIT
EPSS
1.71%
76.0th percentile
DbGate is cross-platform database manager. Versions 7.1.8 and prior are vulnerable to authenticated Remote Code Execution (RCE). Any user with valid DbGate credentials can execute arbitrary OS commands as root by exploiting an unsanitized `functionName` parameter in the `/runners/load-reader` endpoint. The `require = null` mitigation is trivially bypassed via dynamic `import()`. Version 7.1.9 contains a patch.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| dbgate | dbgate | < 7.1.9 | 7.1.9 |
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
DbGate up to 7.1.8 /runners/load-reader functionName os command injection
vuldb·2026-07-23·CVSS 9.4
CVE-2026-47670 [CRITICAL] DbGate up to 7.1.8 /runners/load-reader functionName os command injection
A vulnerability marked as critical has been reported in DbGate up to 7.1.8. The impacted element is an unknown function of the file /runners/load-reader. Performing a manipulation of the argument functionName results in os command injection.
This vulnerability is known as CVE-2026-47670. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to upgrade the affected component.
GHSA
Authenticated Remote Code Execution via loadReader functionName code injection in DbGate
ghsa·2026-06-05
CVE-2026-47670 [CRITICAL] CWE-77 Authenticated Remote Code Execution via loadReader functionName code injection in DbGate
Authenticated Remote Code Execution via loadReader functionName code injection in DbGate
### Summary
DbGate is vulnerable to authenticated Remote Code Execution (RCE). Any user with valid DbGate credentials can execute arbitrary OS commands as root by exploiting an unsanitized `functionName` parameter in the `/runners/load-reader` endpoint. The `require = null` mitigation is trivially bypassed via dynamic `import()`.
### Details
**Code injection via `functionName` in loadReader**
The `/runners/load-reader` endpoint interpolates the `functionName` parameter directly into a dynamically generated JavaScript script template without any sanitization:
```javascript
// packages/api/src/controllers/runners.js (loadReader / loaderScriptTemplate)
const reader = await dbgateApi.${functionName}
No detection rules found.
Nuclei
DbGate - Remote Code Execution via Dynamic Import Bypass
nuclei·CVSS 9.4
CVE-2026-47670 DbGate - Remote Code Execution via Dynamic Import Bypass
DbGate - Remote Code Execution via Dynamic Import Bypass
DbGate versions <= 7.1.8 are vulnerable to authenticated remote code execution via the POST /runners/load-reader endpoint. The functionName parameter is directly interpolated into a JavaScript code template without sanitization. The require=null mitigation is bypassed via dynamic import().
Template:
id: CVE-2026-47670
info:
name: DbGate - Remote Code Execution via Dynamic Import Bypass
author: theamanrawat
severity: critical
description: |
DbGate versions <= 7.1.8 are vulnerable to authenticated remote code execution via the POST /runners/load-reader endpoint. The functionName parameter is directly interpolated into a JavaScript code template without sanitization. The require=null mitigation is bypassed via dynamic import().
impa
No writeups or analysis indexed.
2026-07-23
Published