pgadmin

4 records · 4 with a public proof-of-concept

Disclosed vulnerabilities where the NVD names pgadmin as an affected vendor, highest CVSS first.

  1. CRITICAL 9.8CVE-2026-86863public PoC

    pgAdmin 4's Webserver authentication source is intended to accept an identity asserted by the web server or reverse proxy in front of pgAdmin, delivered through the WSGI/CGI environment. WebserverAuthentication.get_user() read config.WEBSERVER_REMOTE_USER from…

    pgadmin 4

    AI risk analysis on Exploit-DB.ai →

  2. HIGH 8.8CVE-2026-86864public PoC

    pgAdmin 4's Backup tool appended the client-supplied 'database' field from the /backup/job/<sid>/object request to the pg_dump argument vector as a bare trailing positional argument, without validation. Because pg_dump parses its options with getopt_long, whic…

    pgadmin 4

    AI risk analysis on Exploit-DB.ai →

  3. MEDIUM 6.5CVE-2026-86862public PoC

    pgAdmin 4's Restore and Maintenance tools passed the client-supplied 'database' field directly as the value of the --dbname option given to pg_restore and psql. libpq expands a database name containing an equals sign into a full connection string, and connecti…

    pgadmin 4

    AI risk analysis on Exploit-DB.ai →

  4. MEDIUM 5.9CVE-2026-86861public PoC

    pgAdmin 4's File Manager save_file endpoint, which backs saving from the Query Tool and ERD, validated the requested path with Filemanager.check_access_permission() and then opened the file for writing with a plain open() call. CVE-2026-7819 had previously har…

    pgadmin 4

    AI risk analysis on Exploit-DB.ai →