DbGate - RCE (CVE-2026-47670)
Description
DbGate is affected by an authenticated remote code execution vulnerability in the /runners/load-reader endpoint. The functionName parameter is not properly sanitized, and the existing require = null sandbox restriction is trivially bypassed using dynamic import() statements. An authenticated attacker can send a crafted POST request to execute arbitrary JavaScript, leading to OS-level command execution on the host. The vulnerability affects DbGate versions <= 7.1.8 and is fixed in 7.1.9.
psychologyCrowdSec Analysis
CVE-2026-47670 is an authenticated remote code execution vulnerability in DbGate (versions <= 7.1.8). The /runners/load-reader endpoint fails to sanitize the functionName parameter, and the sandbox's require = null protection is bypassed via dynamic import(), allowing any authenticated user to execute arbitrary code and OS commands on the host. Organizations should upgrade to DbGate 7.1.9 or later and restrict access to trusted users.
CrowdSec has been tracking this vulnerability and its exploits since 24th of June 2026.
CrowdSec has not observed any significant exploitation activity targeting CVE-2026-47670 across its network. As a result, no community-driven trend analysis is available for this vulnerability at this time.
Attackers exploit the /runners/load-reader endpoint by sending crafted POST requests with malicious JavaScript in the functionName parameter, enabling remote code execution on vulnerable DbGate instances. This attack requires authentication and typically targets the /runners/load-reader and /jsldata/get-rows endpoints to execute OS commands and retrieve their output.
Full Intelligence Available
Connect your API key to access CrowdSec scores, exploit timelines, and attacker IPs.
| Event | Date |
|---|---|
| CVE Published | 2026-06-05 |
| Rule Released | 2026-06-24 |
Related Weaknesses
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.