CVE-2026-85176: Dbgate

High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.

DbGate fails to validate jslid parameters in the jsldata controller, allowing authenticated users to read and write arbitrary files via file:// scheme resolution. Attackers can exploit getJslFileName() to bypass directory containment and access sensitive files including encrypted database credentials stored in connections configuration.

Affected products

  • Dbgate Dbgate: up to and including 7.2.6

Published 2026-09-03. Last modified 2026-09-23.