Skip to content

Known CVE

DbGate - Remote Code Execution via Anonymous JWT

DbGate contains a remote code execution vulnerability exploitable by unauthenticated attackers. The /auth/login endpoint issues anonymous JWT tokens without credentials, and the /runners/start endpoint accepts JavaScript payloads that execute via Node.js child_process, allowing arbitrary command execution on the server.

CVE-2026-47668

Critical2026CVSS 9.8CWE-94

cve2026 · dbgate · rce · oast · unauth

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website