CVE-2026-47668

CRITICAL NUCLEI

DbGate: Unauthenticated Remote Code Execution via JSON Script Runner

Title source: cna
STIX 2.1

Exploitation Summary

CVE-2026-47668 has a Nuclei detection template available — see the Nuclei card below for the Shodan/FOFA recon queries.

Description

DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST /runners/start`) allows remote code execution via code injection in the `functionName` parameter of JSON script `assign` commands. The `functionName` value is interpolated directly into dynamically generated JavaScript source code via string concatenation. The generated code is then executed in a forked Node.js child process. Version 7.1.9 contains a patch.

Nuclei Templates (1)

DbGate - Remote Code Execution via Anonymous JWT
CRITICALVERIFIEDby benharvey-sage
Shodan: http.title:"DbGate"
FOFA: title="DbGate"

Scores

CVSS v3 10.0
EPSS 0.0434
EPSS Percentile 90.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-1188 CWE-20 CWE-94
Status published
Products (1)
dbgate/dbgate < 7.1.9
Published Jul 23, 2026
Tracked Since Jul 23, 2026