CVE-2026-85176 UNKNOWN

CVE-2026-85176

Published: 2026-09-03

Description

DbGate fails to validate jslid parameters in the jsldata controller, allowing authenticated users to read and write arbitrary files via file:// scheme resolution. Attackers can exploit getJslFileName() to bypass directory containment and access sensitive files including encrypted database credentials stored in connections configuration.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…