CVE-2026-101067 Details
Description
A vulnerability was identified in dbgate up to 6.8.1/7.0.2/7.1.8/7.2.5/7.3.1. This affects the function saveUploadedFile of the file files.js of the component save-uploaded-file Endpoint. Such manipulation of the argument filePath/fileName leads to path traversal. The attack may be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
A critical path traversal vulnerability has been identified in DbGate versions through 7.2.5 and 7.3.1. The issue resides in the saveUploadedFile function within the files.js module, specifically at the files/save-uploaded-file endpoint. This vulnerability allows remote attackers to manipulate the filePath and fileName parameters, leading to unauthorized file access and arbitrary file writes on the server.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/0xGenesi/CVE/blob/main/dbgate_save_uploaded_file_path_traversal.md | [email protected] | ExploitTechnical Description |
| https://vuldb.com/cve/CVE-2026-101067 | [email protected] | AdvisoryPartial Content |
| https://vuldb.com/submit/929029 | [email protected] | Technical Description |
| https://vuldb.com/vuln/410925 | [email protected] | AdvisoryExploitPartial Content |
| https://vuldb.com/vuln/410925/cti | [email protected] | AdvisoryPermission Required |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| dbgate | <= 6.8.1 (semver) <= 7.0.2 (semver) <= 7.1.8 (semver) <= 7.2.5 (semver) <= 7.3.1 (semver) |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 28, 2026 | New CVE Received | [email protected] |
Volerion