CVE-2026-85176
DbGate fails to validate jslid parameters in the jsldata controller, allowing authenticated users to read and write arbitrary files via file:// scheme resolution. Attackers can exploit getJslFileName() to bypass directory containment and access sensitive files including encrypted database credentials stored in connections configuration.
- Published Sep 3, 2026
- CVSS 8.7 high
- 0.6% chance of exploitation in the next 30 days (EPSS)