A critical remote code execution vulnerability (CVE-2026-47668, CVSS 10.0) exists in DbGate versions 7.1.8 and prior. The vulnerability resides in the JSON script runner's handling of `assign` commands, where the `functionName` parameter is directly interpolated into dynamically generated JavaScript code via string concatenation. This allows attackers to inject and execute arbitrary code in a forked Node.js child process. The flaw affects all deployments of DbGate prior to version 7.1.9. Successful exploitation could enable full system compromise, data exfiltration, or lateral movement within networks. Immediate remediation is required due to the high severity and remote exploitability. Affected systems should upgrade to DbGate 7.1.9, which contains a patch addressing the unsafe code interpolation in the script runner. No workarounds are available for versions before 7.1.9. Organizations using DbGate are advised to prioritize patching to eliminate exposure to this critical vulnerability.