Summary
CVE-2026-47668 is a critical unauthenticated Remote Code Execution (RCE) vulnerability in DbGate, a cross-platform web-based database manager. Affecting all versions up to and including 7.1.8, the flaw resides in DbGate’s JSON script runner endpoint, where user-supplied input is interpolated directly into dynamically generated JavaScript without sanitization and subsequently executed in a forked Node.js child process. The vulnerability carries a maximum CVSS v3.1 base score of 10.0 (Critical) and requires no authentication, no user interaction, and no special privileges to exploit.
Technical details
- Root cause: The
assignCore()method inScriptWriter.tsconstructs executable JavaScript by directly concatenating the attacker-controlledfunctionName(andvariableName) parameters from JSONassigncommands into generated source code without any input validation or sanitization. By default, DbGate ships with authentication disabled, meaning the endpoint is reachable by any unauthenticated network peer. - Trigger condition: An attacker sends a crafted HTTP POST request to the
/runners/startendpoint containing a JSON script with a maliciousassigncommand. The injected payload (e.g.,"x;MALICIOUS_CODE;//") forms syntactically valid JavaScript that causes arbitrary code to execute before the intended code path. - Attack vector: Network-accessible, no authentication required (PR:N, UI:N). On default DbGate deployments where authentication is disabled, exploitation is fully unauthenticated. Even on authenticated deployments, any authorized user can trigger the vulnerability.
- Execution context: The injected code runs inside a forked Node.js child process with access to system resources, enabling arbitrary OS command execution at the privilege level of the DbGate process.
- Impact: Full remote code execution — including arbitrary OS command execution, credential and data exfiltration, lateral movement within internal networks, and complete host takeover. The CVSS scope change (S:C) reflects that exploitation can affect resources beyond the DbGate process itself.
- Public exploit availability: A public proof-of-concept exploit is available at https://github.com/Nxploited/CVE-2026-47668, and an automated detection template has been merged into the nuclei-templates project.
Affected software
- DbGate (dbgate / dbgate-serve): all versions ≤ 7.1.8
Severity
- CVSS v3.1 Base Score: 10.0 (Critical)
- Vector String:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H - CWEs: CWE-94 (Code Injection), CWE-20 (Improper Input Validation), CWE-1188 (Insecure Default Initialization)
Mitigation and recommended actions
- Immediate patch: Upgrade DbGate / dbgate-serve to version 7.1.9 or later, which introduces validation for function and file names and resolves the code injection flaw.
- Enable authentication: If immediate patching is not possible, explicitly configure authentication on DbGate deployments rather than relying on the default anonymous mode. Restrict access to the
/runners/startendpoint to trusted users and networks only. - Network isolation: Ensure DbGate instances are not exposed directly to the internet. Place instances behind a firewall or VPN and restrict inbound access to the management interface ports (commonly 3000 or 5003).
- Audit logs: Review application logs for unexpected or unauthorized POST requests to
/runners/startas an indicator of exploitation attempts.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

