CVE-2026-47668Patch

MEDIUMCVSS 10.0 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST /runners/start`) allows remote code execution via code injection in the `functionName` parameter of JSON script `assign` commands. The `functionName` value is interpolated directly into dynamically generated JavaScript source code via string concatenation. The generated code is then executed in a forked Node.js child process. Version 7.1.9 contains a patch.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-94CWE-1188

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 8 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 8 signals
  • Disclosure: 1 classified signal
  • Peaked 4d ago at 2 mentions (2026-06-05); latest day: 1
  • 8 total mentions across 7 days

Deep dive

Activity timeline8 mentions / 7d
01122Mentions · 2026-05-26: 1Mentions · 2026-05-27: 1Mentions · 2026-06-05: 2Mentions · 2026-06-08: 1Mentions · 2026-07-24: 1Mentions · 2026-07-30: 1Mentions · 2026-07-31: 1PoC Mentioned / Linked · 2026-05-26: 1PoC Mentioned / Linked · 2026-05-27: 1PoC Mentioned / Linked · 2026-07-31: 1Exploit Tool / Code · 2026-05-26: 1Patch / Workaround · 2026-06-05: 2Patch / Workaround · 2026-06-08: 1Patch / Workaround · 2026-07-24: 1Technical Details · 2026-05-26: 1Technical Details · 2026-05-27: 1Technical Details · 2026-06-05: 2Technical Details · 2026-06-08: 1Technical Details · 2026-07-24: 1Technical Details · 2026-07-30: 1Technical Details · 2026-07-31: 105-2605-2706-0506-0807-2407-3007-31
Signal classification4 categories
Patch
450.0%
PoC
225.0%
Disclosure
112.5%
Exploit
112.5%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-05-261
PoC1
2026-05-271
PoC1
2026-06-052
Patch2
2026-06-081
Patch1
2026-07-241
Patch1
2026-07-301
Disclosure1
2026-07-311
Exploit1
Full discourse8 posts
  • Nxploited@Nxploited
    PoC

    CVE-2026-47668 — DbGate Remote Code Execution PoC: https://github.com/Nxploited/CVE-2026-47668 #CyberSecurity #InfoSec #EthicalHacking #Hacking #BugBounty #RedTeam #PenTesting

    Post summary

    A GitHub repository providing a proof‑of‑concept exploit for CVE‑2026‑47668, a Remote Code Execution vulnerability in DbGate, has been shared.

    16021101.8K
    120 followersView on X
  • Kaitan ID Security@KaitanSecurity
    Exploit

    🧨 DbGate JSON Script Runner — Unauthenticated RCE with Public Exploit (CVSS 10.0) CVE-2026-47668 affects DbGate versions 7.1.8 and prior. The cross-platform database manager's JSON script runner endpoint (POST /runners/start) permits unauthenticated remote code…

    Post summary

    CVE-2026-47668 exposes an unauthenticated RCE in DbGate with a CVSS of 10.0; a public exploit exists but no patch or mitigation is discussed.

    1000038
    87 followersView on X
  • Cyber Netsec IO@NetSecIO
    Patch

    🔥 CRITICAL ALERT: Two CVSS 10.0 vulnerabilities disclosed! 🚨 Unauthenticated bypass in Azure HorizonDB (CVE-2026-48567) & RCE in DbGate (CVE-2026-47668) pose extreme risk to cloud environments. Patch and restrict access NOW! #CVE #RCE #CyberSecurity 🌐 cyber[.]netsecops[.]io https://t.co/nfPrjtoRA2

    Post summary

    The tweet alerts about two critical CVSS 10.0 vulnerabilities affecting Azure HorizonDB and DbGate, urging immediate patching and access restrictions.

    0001068
    59 followersView on X
  • NotCVE@notCVE
    Disclosure

    🎯 Most likely to be exploited next (EPSS): • CVE-2026-6516 — EPSS 4.7% · CVSS 10 • CVE-2026-47668 — EPSS 4.3% · CVSS 10 • CVE-2026-17191 — EPSS 2.8% · CVSS 9.1 📄 Full weekly tables → https://github.com/notcve/reports/blob/main/weekly/2026-07-30.md

    Post summary

    The message lists three high‑CVSS CVEs with EPSS scores, offering a link to a weekly report but lacking details on PoC, exploitation, or patches.

    0000049
    62 followersView on X
  • ADK Cyber@ADKCyber
    Patch

    Critical CVE-2026-47668 (CVSS 10.0) impacts DbGate 7.1.8 and earlier with remote code execution. Update promptly if using this database manager. https://nvd.nist.gov/vuln/detail/CVE-2026-47668 via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability #AI #MachineLearning https://t.co/CtHLg32KYt

    Post summary

    The tweet announces a critical remote-code-execution vulnerability in DbGate 7.1.8 and earlier, encourages users to update promptly, but does not provide details of a PoC or active exploitation.

    0000035
    89 followersView on X
  • SecAlerts@SecAlertsCo
    Patch

    CVSS 10 unauthenticated RCE in DbGate. CVE-2026-47668 lets attackers inject code via the `functionName` param in JSON script commands — no auth, no interaction, full system compromise. Upgrade dbgate-serve to v7.1.9 now. https://secalerts.co/vulnerability/CVE-2026-47668 https://t.co/W80hOLlQt1

    Post summary

    The post announces a critical CVE‑2026‑47668 causing unauthenticated RCE in DbGate via the functionName parameter, and advises upgrading to v7.1.9 to apply the patch.

    0000069
    830 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 Multiple Critical Vulnerabilities Disclosed in DbGate Several severe vulnerabilities in DbGate can allow attackers to achieve remote code execution: • CVE-2026-47668 - Unauthenticated RCE via JSON Script Runner (dbgate-serve) • CVE-2026-47669 - Zip Slip arbitrary file write leading to RCE • CVE-2026-47670 - Authenticated RCE via functionName injection (dbgate-api) 👉 Affected: DbGate <= 7.1.8 ✅ Fix: Upgrade to 7.1.9 or later

    Post summary

    The post announces new critical vulnerabilities in DbGate, details the exploitation methods, and provides a patch recommendation to upgrade to version 7.1.9 or later.

    0000060
    207 followersView on X
  • VulnTracker@vuln_tracker
    PoC

    Unauthenticated RCE on DbGate. PoC is live. CVE-2026-47668 - no login needed to execute code remotely on the database management tool trusted by devs and DBAs everywhere. Database tools are high-value, low-security targets. This one just got a lot worse. http://VulnTracker.io

    Post summary

    The post announces a live Proof of Concept for CVE-2026-47668, highlighting an unauthenticated remote code execution vulnerability in DbGate, but does not provide exploit code, patch information, or active exploitation reports.

    00000165
    655 followersView on X

Explore more