CVE-2026-101066 Details
Description
A vulnerability was determined in dbgate up to 7.3.1. The impacted element is the function createLink of the file packages/api/src/controllers/archive.js of the component Archive Link Creation. This manipulation of the argument linkedFolder causes path traversal. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
A critical path traversal vulnerability has been identified in DbGate versions through 7.3.1. The issue resides in the Archive Link Creation component, specifically within the createLink function of packages/api/src/controllers/archive.js. The vulnerability arises from inadequate validation of the linkedFolder parameter, allowing attackers to manipulate the input and traverse the file system. This flaw can be exploited remotely without authentication, particularly in the default DbGate Docker deployment, which enables anonymous access.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 28, 2026CISA-ADP
Assessed Sep 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/0xGenesi/CVE/blob/main/dbgate_archive_link_path_traversal.md | [email protected] | ExploitTechnical Analysis |
| https://vuldb.com/cve/CVE-2026-101066 | [email protected] | AdvisoryExploit |
| https://vuldb.com/submit/929026 | [email protected] | Technical Description |
| https://vuldb.com/vuln/410924 | [email protected] | AdvisoryExploitPartial Content |
| https://vuldb.com/vuln/410924/cti | [email protected] | AdvisoryPermission Required |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| dbgate | <= 7.2.5 (semver) <= 7.3.1 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 28, 2026 | New CVE Received | [email protected] |
| Sep 28, 2026 | CVE Modified | CISA-ADP |
Volerion