← Terug naar overzicht

CVE-2026-85176 affects DbGate through version 7.2.6, where the jsldata controller fails to properly validate jslid parameters. Authenticated users can exploit this flaw to read and write arbitrary files on the server via file:// scheme resolution. The vulnerability resides in the getJslFileName() utility function, which can be manipulated to bypass directory containment controls. Attackers with valid credentials can access sensitive files outside intended directories, including encrypted database credentials stored in connection configurations. This represents a significant risk for deployments where DbGate is exposed to untrusted authenticated users. The issue has been documented in a GitHub issue and independently reported by VulnCheck. No patch version is specified beyond the affected 7.2.6 release. The vulnerability falls into the category of path traversal and improper input validation leading to arbitrary file access.

Affected products

  • DbGate v7.2.6

Related CVE's

  • CVE-2026-85176

Categories

  • Data Breach & Exfiltration
  • Database & Storage
  • Web Technologies