What is CVE-2026-47668?
CVE-2026-47668 is a critical vulnerability in the DbGate database manager. In versions 7.1.8 and prior, the JSON script runner at 'POST /runners/start' allows remote code execution (RCE) through code injection in the 'functionName' parameter of JSON script 'assign' commands, where the value is interpolated directly into dynamic code. Affected users should immediately update and restrict access to the vulnerable endpoint.
Azərbaycanca: CVE-2026-47668, DbGate verilənlər bazası menecerində aşkarlanmış kritik boşluqdur. 7.1.8 və əvvəlki versiyalarda "POST /runners/start" JSON script runner funksionallığı, "functionName" parametrinə birbaşa kod yeridilməsi yolu ilə uzaqdan kod icrasına (RCE) imkan verir. Təsirlənən istifadəçilər dərhal proqramı yeniləməli və ya həssas funksionallığa girişi məhdudlaşdırmalıdır.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
Which DbGate versions are affected by CVE-2026-47668?
CVE-2026-47668 affects DbGate versions 7.1.8 and all prior versions.
What threat arises from exploiting CVE-2026-47668?
This vulnerability allows for remote code execution (RCE) through the JSON script runner functionality at 'POST /runners/start'.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.