CVE-2026-86864
- EPSS 0.38%
- Veröffentlicht 17.09.2026 15:31:00
- Zuletzt bearbeitet 21.09.2026 17:27:38
pgAdmin 4's Backup tool appended the client-supplied 'database' field from the /backup/job/<sid>/object request to the pg_dump argument vector as a bare trailing positional argument, without validation. Because pg_dump parses its options with getopt_...
CVE-2026-86863
- EPSS 0.36%
- Veröffentlicht 17.09.2026 15:30:58
- Zuletzt bearbeitet 21.09.2026 17:27:28
pgAdmin 4's Webserver authentication source is intended to accept an identity asserted by the web server or reverse proxy in front of pgAdmin, delivered through the WSGI/CGI environment. WebserverAuthentication.get_user() read config.WEBSERVER_REMOTE...
CVE-2026-86862
- EPSS 0.2%
- Veröffentlicht 17.09.2026 15:30:56
- Zuletzt bearbeitet 21.09.2026 17:27:19
pgAdmin 4's Restore and Maintenance tools passed the client-supplied 'database' field directly as the value of the --dbname option given to pg_restore and psql. libpq expands a database name containing an equals sign into a full connection string, an...
- EPSS 0.44%
- Veröffentlicht 17.09.2026 15:30:51
- Zuletzt bearbeitet 21.09.2026 17:26:49
pgAdmin 4's File Manager save_file endpoint, which backs saving from the Query Tool and ERD, validated the requested path with Filemanager.check_access_permission() and then opened the file for writing with a plain open() call. CVE-2026-7819 had prev...
CVE-2026-17566
- EPSS 0.41%
- Veröffentlicht 31.07.2026 16:17:00
- Zuletzt bearbeitet 05.08.2026 20:00:10
pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-supplied SQL query into a Jinja template and passing the rendered line to psql via --command. To stop an attacker from breaking out of the (...) wrappe...
- EPSS 0.38%
- Veröffentlicht 31.07.2026 16:16:59
- Zuletzt bearbeitet 05.08.2026 20:07:14
The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlparse, as exactly one non-transaction-control statement before running it inside a BEGIN TRANSACTION REA...
CVE-2026-17350
- EPSS 0.22%
- Veröffentlicht 31.07.2026 16:16:59
- Zuletzt bearbeitet 05.08.2026 20:09:45
The per-tool permission system (custom roles / role-based tool permissions, introduced in pgAdmin 4 9.3) did not enforce its permission check consistently. In SERVER mode, pgAdmin 4 gates each tool behind a per-tool Flask-Security permission, but the...
CVE-2026-17349
- EPSS 0.29%
- Veröffentlicht 31.07.2026 16:16:59
- Zuletzt bearbeitet 05.08.2026 20:17:21
/misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, when passed the id of an existing server, clones that server via Server.clone(), which copies every column from the source row, including user_id, share...
CVE-2026-17348
- EPSS 0.24%
- Veröffentlicht 31.07.2026 16:16:59
- Zuletzt bearbeitet 05.08.2026 20:21:02
In SERVER mode, pgAdmin 4 enforces authentication per route via the @pga_login_required decorator; the application's before_request hook only handles desktop-mode auto-login and the Kerberos/Webserver-auth redirect, so any route shipped without the d...
CVE-2026-17347
- EPSS 0.3%
- Veröffentlicht 31.07.2026 16:16:59
- Zuletzt bearbeitet 07.08.2026 17:42:20
The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an external command that returns a per-user encryption key, with %u in the configured string replaced by the current user's name. The previous implementati...