CVE-2026-97226

MEDIUM Status: Deferred

CVSS Scores

CVSS v3.x Base Score
6.3
MEDIUM
CVSS v2 Base Score
6.5
MEDIUM

Description

A vulnerability has been found in DbGate up to 7.2.5/7.3.1-premium-beta.1. This impacts the function fs.readFile of the file packages/api/src/controllers/files.js of the component files-style Endpoint. The manipulation of the argument filePath/uri leads to path traversal. It is possible to initiate the attack remotely. The vendor was contacted early about this disclosure but did not respond in any way.

Published
September 24, 2026 4:17 PM
Last Modified
September 24, 2026 6:19 PM
Source
[email protected]

Weaknesses (CWE)

CWE-22

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.