CVE-2026-85176: Dbgate
High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.
DbGate fails to validate jslid parameters in the jsldata controller, allowing authenticated users to read and write arbitrary files via file:// scheme resolution. Attackers can exploit getJslFileName() to bypass directory containment and access sensitive files including encrypted database credentials stored in connections configuration.
Affected products
- Dbgate Dbgate: up to and including 7.2.6
Published 2026-09-03. Last modified 2026-09-23.