PT-2026-56272 · Dbi+2 · Dbi+2

·

CVE-2026-14380

·

Published

2026-07-07

·

Updated

2026-09-09

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions DBI versions prior to 1.650
Description Code injection is possible via a caller-influenced Profile attribute. When a string is assigned to this attribute, the software splits it into path, package, and arguments, then interpolates the package part in a string eval without validating the package name. This allows arbitrary Perl code execution, including system command calls, if an attacker controls the Profile attribute. This attribute can be influenced through the DBI PROFILE environment variable, direct attribute assignment, or a DSN driver-attribute clause dbi:Driver(Profile=>SPEC):db. Network-exposed DBI::Gofer or DBI::ProxyServer instances are particularly susceptible if the per-request DSN reaches the Profile attribute, enabling remote code execution on the broker host.
Recommendations Update to version 1.650 or later.

Exploit

Fix

DoS

RCE

Eval Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:49514
ALSA-2026:49612
ALSA-2026:52772
ALSA-2026:62667
ALSA-2026:65887
ALSA-2026:66179
AZL-92205
CVE-2026-14380
ECHO-313A-EE2B-ABF6
GHSA-CH8W-HXC2-V557
OPENSUSE-SU-2026:11234-1
OPENSUSE-SU-2026:21293-1
SUSE-SU-2026:22592-1
SUSE-SU-2026:22623-1
SUSE-SU-2026:3283-1
SUSE-SU-2026:3415-1
SUSE-SU-2026:3461-1

Affected Products

Dbi
Red Os
Rocky Linux