Pgadmin

Pgadmin 4

46 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.38%
  • Veröffentlicht 17.09.2026 15:31:00
  • Zuletzt bearbeitet 21.09.2026 17:27:38

pgAdmin 4's Backup tool appended the client-supplied 'database' field from the /backup/job/<sid>/object request to the pg_dump argument vector as a bare trailing positional argument, without validation. Because pg_dump parses its options with getopt_...

  • EPSS 0.36%
  • Veröffentlicht 17.09.2026 15:30:58
  • Zuletzt bearbeitet 21.09.2026 17:27:28

pgAdmin 4's Webserver authentication source is intended to accept an identity asserted by the web server or reverse proxy in front of pgAdmin, delivered through the WSGI/CGI environment. WebserverAuthentication.get_user() read config.WEBSERVER_REMOTE...

Exploit
  • EPSS 0.2%
  • Veröffentlicht 17.09.2026 15:30:56
  • Zuletzt bearbeitet 21.09.2026 17:27:19

pgAdmin 4's Restore and Maintenance tools passed the client-supplied 'database' field directly as the value of the --dbname option given to pg_restore and psql. libpq expands a database name containing an equals sign into a full connection string, an...

Exploit
  • EPSS 0.44%
  • Veröffentlicht 17.09.2026 15:30:51
  • Zuletzt bearbeitet 21.09.2026 17:26:49

pgAdmin 4's File Manager save_file endpoint, which backs saving from the Query Tool and ERD, validated the requested path with Filemanager.check_access_permission() and then opened the file for writing with a plain open() call. CVE-2026-7819 had prev...

  • EPSS 0.41%
  • Veröffentlicht 31.07.2026 16:17:00
  • Zuletzt bearbeitet 05.08.2026 20:00:10

pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-supplied SQL query into a Jinja template and passing the rendered line to psql via --command. To stop an attacker from breaking out of the (...) wrappe...

  • EPSS 0.38%
  • Veröffentlicht 31.07.2026 16:16:59
  • Zuletzt bearbeitet 05.08.2026 20:07:14

The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlparse, as exactly one non-transaction-control statement before running it inside a BEGIN TRANSACTION REA...

  • EPSS 0.22%
  • Veröffentlicht 31.07.2026 16:16:59
  • Zuletzt bearbeitet 05.08.2026 20:09:45

The per-tool permission system (custom roles / role-based tool permissions, introduced in pgAdmin 4 9.3) did not enforce its permission check consistently. In SERVER mode, pgAdmin 4 gates each tool behind a per-tool Flask-Security permission, but the...

  • EPSS 0.29%
  • Veröffentlicht 31.07.2026 16:16:59
  • Zuletzt bearbeitet 05.08.2026 20:17:21

/misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, when passed the id of an existing server, clones that server via Server.clone(), which copies every column from the source row, including user_id, share...

  • EPSS 0.24%
  • Veröffentlicht 31.07.2026 16:16:59
  • Zuletzt bearbeitet 05.08.2026 20:21:02

In SERVER mode, pgAdmin 4 enforces authentication per route via the @pga_login_required decorator; the application's before_request hook only handles desktop-mode auto-login and the Kerberos/Webserver-auth redirect, so any route shipped without the d...

  • EPSS 0.3%
  • Veröffentlicht 31.07.2026 16:16:59
  • Zuletzt bearbeitet 07.08.2026 17:42:20

The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an external command that returns a per-user encryption key, with %u in the configured string replaced by the current user's name. The previous implementati...