{"id":"CVE-2026-97226","published":"2026-09-24T16:17:29.090","lastModified":"2026-09-24T18:19:09.063","description":"A vulnerability has been found in DbGate up to 7.2.5/7.3.1-premium-beta.1. This impacts the function fs.readFile of the file packages/api/src/controllers/files.js of the component files-style Endpoint. The manipulation of the argument filePath/uri leads to path traversal. It is possible to initiate the attack remotely. The vendor was contacted early about this disclosure but did not respond in any way.","cvssScore":6.3,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","cwes":["CWE-22"],"vendors":[],"products":[],"references":[{"url":"https://vuldb.com/cve/CVE-2026-97226","tags":[]},{"url":"https://vuldb.com/submit/908139","tags":[]},{"url":"https://vuldb.com/vuln/409320","tags":[]},{"url":"https://vuldb.com/vuln/409320/cti","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}