CVE-2026-101066High· 7.3▾ MidnightPoC availableA vulnerability was determined in dbgate up to 7.3.1. The impacted element is the function createLink of the file packages/api/src/controllers/archive.js of the component Archive Link Creation. This manipulation of the argument linkedFol…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 40.2 · likelihood 0 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
A vulnerability was determined in dbgate up to 7.3.1. The impacted element is the function createLink of the file packages/api/src/controllers/archive.js of the component Archive Link Creation. This manipulation of the argument linkedFolder causes path traversal. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-101068Medium· 6.5A security flaw has been discovered in dbgate up to 7.3.1
CVE-2026-101070Medium· 5.3dbgate Files Endpoint runners.js files path traversal
CVE-2026-101067High· 7.3A vulnerability was identified in dbgate up to 6.8.1/7.0.2/7.1.8/7.2.5/7.3.1
CVE-2026-101069Medium· 6.5A weakness has been identified in dbgate up to 7.3.1
CVE-2026-97226Medium· 6.3A vulnerability has been found in DbGate up to 7.2.5/7.3.1-premium-beta.1
CVE-2026-97225Medium· 6.3A flaw has been found in DbGate up to 7.2.5-beta.5