pgadmin
4 records · 4 with a public proof-of-concept
Disclosed vulnerabilities where the NVD names pgadmin as an affected vendor, highest CVSS first.
- CRITICAL 9.8CVE-2026-86863public PoC
pgAdmin 4's Webserver authentication source is intended to accept an identity asserted by the web server or reverse proxy in front of pgAdmin, delivered through the WSGI/CGI environment. WebserverAuthentication.get_user() read config.WEBSERVER_REMOTE_USER from…
pgadmin 4
- HIGH 8.8CVE-2026-86864public PoC
pgAdmin 4's Backup tool appended the client-supplied 'database' field from the /backup/job/<sid>/object request to the pg_dump argument vector as a bare trailing positional argument, without validation. Because pg_dump parses its options with getopt_long, whic…
pgadmin 4
- MEDIUM 6.5CVE-2026-86862public PoC
pgAdmin 4's Restore and Maintenance tools passed the client-supplied 'database' field directly as the value of the --dbname option given to pg_restore and psql. libpq expands a database name containing an equals sign into a full connection string, and connecti…
pgadmin 4
- MEDIUM 5.9CVE-2026-86861public PoC
pgAdmin 4's File Manager save_file endpoint, which backs saving from the Query Tool and ERD, validated the requested path with Filemanager.check_access_permission() and then opened the file for writing with a plain open() call. CVE-2026-7819 had previously har…
pgadmin 4