logo

CVE-2026-47668: Unauthenticated RCE Vulnerability in DbGate

ID: bbfbccfe-da64-5235-af56-016d24ebd887

STIX ID: report--bbfbccfe-da64-5235-af56-016d24ebd887

Feed Name: ThreatCluster

Threat Score
90/100

Date Published: 2026-06-06

Date Updated: 2026-06-08

...
...

DbGate contains a critical unauthenticated remote code execution vulnerability (CVE-2026-47668) in its JSON script runner that allows attackers to inject code via the functionName parameter and obtain full Node.js runtime access; systems using default deployments with authentication disabled are particularly at risk. Apply the vendor patch (7.1.9 or later), enforce authentication, and restrict access to the /runners/start endpoint and related APIs until patched.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.