CVE-2026-47668: Unauthenticated RCE Vulnerability in DbGate
ID: bbfbccfe-da64-5235-af56-016d24ebd887
STIX ID: report--bbfbccfe-da64-5235-af56-016d24ebd887
Feed Name: ThreatCluster
Threat Score
DbGate contains a critical unauthenticated remote code execution vulnerability (CVE-2026-47668) in its JSON script runner that allows attackers to inject code via the functionName parameter and obtain full Node.js runtime access; systems using default deployments with authentication disabled are particularly at risk. Apply the vendor patch (7.1.9 or later), enforce authentication, and restrict access to the /runners/start endpoint and related APIs until patched.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
