CVE-2026-17348
published 2026-07-31CVE-2026-17348: In SERVER mode, pgAdmin 4 enforces authentication per route via the @pga_login_required decorator; the application's before_request hook only handles…
PriorityP338medium6.5CVSS 3.1
AVNACLPRNUINSUCNILAL
EPSS
0.24%
15.1th percentile
In SERVER mode, pgAdmin 4 enforces authentication per route via the @pga_login_required decorator; the application's before_request hook only handles desktop-mode auto-login and the Kerberos/Webserver-auth redirect, so any route shipped without the decorator is reachable without authentication (CWE-306). This is the same defect class previously fixed as CVE-2026-12046 (the sqleditor close/update_connection routes).
A follow-up sweep, prompted by a report describing an incomplete fix for CVE-2026-12046, found further routes missing @pga_login_required: the Constraints blueprint's nodes and proplist (object listing) routes and its delete route (a state-mutating DELETE that removes table constraints); preferences.get_all_cli (GET, discloses all CLI-settable preference values); debugger.close (DELETE); and schema_diff.close (DELETE). An unauthenticated network client could therefore enumerate constraint metadata, delete table constraints, read preference values, and force-close debugger or schema-diff sessions belonging to other users, without ever authenticating.
Fix adds the missing @pga_login_required decorator (and the corresponding import to the Constraints module) to each of these routes. The change is decorator-only; no behavioral changes to the underlying handlers.
This issue affects pgAdmin 4 in SERVER mode: the Constraints and Debugger routes from 1.0, the Schema Diff close route from 4.18, and preferences.get_all_cli from 8.2, all before 9.17.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| pgadmin | pgadmin_4 | >= 1.0 < 9.17 | 9.17 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
nvdv4.06.9MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
pgadmin-org pgAdmin up to 9.16 Constraints preferences.get_all_cli missing authentication
vuldb·2026-07-31·CVSS 6.5
CVE-2026-17348 [MEDIUM] pgadmin-org pgAdmin up to 9.16 Constraints preferences.get_all_cli missing authentication
A vulnerability marked as critical has been reported in pgadmin-org pgAdmin up to 9.16. The impacted element is the function preferences.get_all_cli of the component Constraints. Performing a manipulation results in missing authentication.
This vulnerability is known as CVE-2026-17348. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to upgrade the affected component.
GHSA
In SERVER mode, pgAdmin 4 enforces authentication per route via the @pga_login_required decorator; the application's before_request hook only handles desktop-mode auto-login and the Kerberos/Webserver
ghsa_unreviewed·2026-07-31·CVSS 9.0
CVE-2026-17348 [CRITICAL] CWE-306 In SERVER mode, pgAdmin 4 enforces authentication per route via the @pga_login_required decorator; the application's before_request hook only handles desktop-mode auto-login and the Kerberos/Webserver
In SERVER mode, pgAdmin 4 enforces authentication per route via the @pga_login_required decorator; the application's before_request hook only handles desktop-mode auto-login and the Kerberos/Webserver-auth redirect, so any route shipped without the decorator is reachable without authentication (CWE-306). This is the same defect class previously fixed as CVE-2026-12046 (the sqleditor close/update_connection routes).
A follow-up sweep, prompted by a report describing an incomplete fix for CVE-2026-12046, found further routes missing @pga_login_required: the Constraints blueprint's nodes and proplist (object listing) routes and its delete route (a state-mutating DELETE that removes table constraints); preferences.get_all_cli (GET, discloses all CLI-settable preference values); debugger.close
Red Hat
pgadmin4: pgAdmin 4: Unauthenticated access allows data manipulation and information disclosure
vendor_redhat·2026-07-31·CVSS 6.5
CVE-2026-17348 [MEDIUM] CWE-306 pgadmin4: pgAdmin 4: Unauthenticated access allows data manipulation and information disclosure
pgadmin4: pgAdmin 4: Unauthenticated access allows data manipulation and information disclosure
A flaw was found in pgAdmin 4. In SERVER mode, an unauthenticated network client could exploit missing authentication controls on specific routes. This vulnerability allows an attacker to enumerate constraint metadata, read sensitive preference values, delete table constraints, and force-close debugger or schema-diff sessions belonging to other users. This could lead to unauthorized data modification, information disclosure, and denial of service for legitimate users.
Statement: This package is not shipped in any Red Hat products, only the Fedora community project.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-17348 pgadmin4: pgAdmin 4: Unauthenticated access allows data manipulation and information disclosure
bugzilla·2026-07-31·CVSS 9.0
CVE-2026-17348 [CRITICAL] CVE-2026-17348 pgadmin4: pgAdmin 4: Unauthenticated access allows data manipulation and information disclosure
CVE-2026-17348 pgadmin4: pgAdmin 4: Unauthenticated access allows data manipulation and information disclosure
In SERVER mode, pgAdmin 4 enforces authentication per route via the @pga_login_required decorator; the application's before_request hook only handles desktop-mode auto-login and the Kerberos/Webserver-auth redirect, so any route shipped without the decorator is reachable without authentication (CWE-306). This is the same defect class previously fixed as CVE-2026-12046 (the sqleditor close/update_connection routes).
A follow-up sweep, prompted by a report describing an incomplete fix for CVE-2026-12046, found further routes missing @pga_login_required: the Constraints blueprint's nodes and proplist (object listing) routes and its delete route (a state-mutating DELETE that removes
Bugzilla
CVE-2026-17348 pgadmin4: pgAdmin 4: Unauthenticated access allows data manipulation and information disclosure [fedora-all]
bugzilla·2026-07-31·CVSS 9.0
CVE-2026-17348 [CRITICAL] CVE-2026-17348 pgadmin4: pgAdmin 4: Unauthenticated access allows data manipulation and information disclosure [fedora-all]
CVE-2026-17348 pgadmin4: pgAdmin 4: Unauthenticated access allows data manipulation and information disclosure [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
In SERVER mode, pgAdmin 4 enforces authentication per route via the @pga_login_required decorator; the application's before_request hook only handles desktop-mode auto-login and the Kerberos/Webserver-auth redirect, so any route shipped without the decorator is reachable without authentication (CWE-306). This is the same defect class previously fixed as CVE-2026-12046 (the sqleditor close/update_connection routes).
A follow-up sweep, prompted by
2026-07-31
Published