Junglewise Threat Intelligence

CVE-2026-78030: DBI arbitrary module load via dbm_type and dbm_mldbm attributes

CVE-2026-78030 · Severity: critical · CVSS 9.8 · Published 2026-09-19

Executive brief

DBI is a Perl database interface library used by applications to access various databases. A flaw in DBD::DBM allows an attacker to load and execute arbitrary Perl modules by manipulating the dbm_type or dbm_mldbm connection attributes, potentially leading to code execution. An attacker with the ability to influence database connection parameters—such as through a DSN string or configuration option—can exploit this to run malicious code.

Technical details

DBD::DBM passes the dbm_type and dbm_mldbm attributes directly to Perl's require function without validating that they are valid module names. Since require treats path-shaped strings as literal filenames rather than consulting @INC, an attacker can traverse the filesystem using relative paths (e.g., "../../Untrusted.pm") to load arbitrary .pm files. The fix validates these attributes using Module::Load and a class name check before loading modules.

Affected products

  • Perl DBI DBI before 1.653

Timeline

  • 2026-09-19: disclosed
  • 2026-08-22: patched: Fix committed to DBI repository

References