Remote Code Execution in DbGate Database Manager by DbGate
CVE-2026-47670
9.4CRITICAL
What is CVE-2026-47670?
DbGate is a cross-platform database management tool with a vulnerability enabling authenticated users to execute arbitrary OS commands as root. This vulnerability arises from an unsanitized 'functionName' parameter in the '/runners/load-reader' endpoint. Despite the implementation of a 'require = null' mitigation, it can be easily bypassed using dynamic 'import()'. Users are advised to upgrade to version 7.1.9, which includes a critical security patch to address this issue.
Affected Version(s)
dbgate < 7.1.9
