CVE-2026-101067High· 7.3▾ TwilightA vulnerability was identified in dbgate up to 6.8.1/7.0.2/7.1.8/7.2.5/7.3.1. This affects the function saveUploadedFile of the file files.js of the component save-uploaded-file Endpoint. Such manipulation of the argument filePath/fileNa…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 40.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A vulnerability was identified in dbgate up to 6.8.1/7.0.2/7.1.8/7.2.5/7.3.1. This affects the function saveUploadedFile of the file files.js of the component save-uploaded-file Endpoint. Such manipulation of the argument filePath/fileName leads to path traversal. The attack may be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-101070Medium· 5.3dbgate Files Endpoint runners.js files path traversal
CVE-2026-101068Medium· 6.5A security flaw has been discovered in dbgate up to 7.3.1
CVE-2026-101066High· 7.3A vulnerability was determined in dbgate up to 7.3.1
CVE-2026-101069Medium· 6.5A weakness has been identified in dbgate up to 7.3.1
CVE-2026-97226Medium· 6.3A vulnerability has been found in DbGate up to 7.2.5/7.3.1-premium-beta.1
CVE-2026-97225Medium· 6.3A flaw has been found in DbGate up to 7.2.5-beta.5