Unauthorized File Access in DbGate Database Manager
CVE-2025-50185

7HIGH

Key Information:

Vendor

Dbgate

Status
Vendor
CVE Published:
26 July 2025

What is CVE-2025-50185?

DbGate, a cross-platform database management solution, is susceptible to unauthorized file access due to insufficient validation of file paths and types in versions 6.6.0 and earlier. This vulnerability permits users with application-level access to retrieve the contents of arbitrary files on the server, bypassing controls intended to restrict file access. The software lacks the necessary checks to validate the content type and file extension before securely reading a file. Consequently, sensitive files, including those typically protected by root user permissions, can be accessed through the application interface. Currently, there is no available fix for this vulnerability, leaving systems at risk.

Affected Version(s)

dbgate <= 6.6.0

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-50185 : Unauthorized File Access in DbGate Database Manager