CVE-2026-101067 | dbgate up to 7.3.1 save-uploaded-file Endpoint files.js saveUploadedFile filePath/fileName path traversal
A vulnerability labeled as critical has been found in dbgate up to 6.8.1/7.0.2/7.1.8/7.2.5/7.3.1. This affects the function saveUploadedFile of the file files.js of the component save-uploaded-file Endpoint. Such manipulation of the argument filePath/fileName leads to path traversal.
This vulnerability is traded as CVE-2026-101067. The attack may be launched remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More