cbcvebase.

Pgadmin 4 vulnerabilities

46 known vulnerabilities affecting pgadmin/pgadmin_4.

Total CVEs
46
CISA KEV
0
Public exploits
5
Exploited in wild
1
Severity breakdown
CRITICAL9HIGH19MEDIUM18

Vulnerabilities

Page 2 of 3
CVE-2026-17346P3HIGHCVSS 8.8≥ 1.0, < 9.172026-07-31
CVE-2026-17346 [HIGH] CVE-2026-17346: The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT ON / pg The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT ON / pgstattuple / pgstatindex templates to it, but missed several sinks that had been placed in test_sql_string_literal_lint.py's ALLOWLIST on the incorrect assumption that schema, table, publication, and subscription names sourced from pg_catalog via the browser tre
nvd
CVE-2025-12763P3HIGHCVSS 8.8fixed in 9.102025-11-13
CVE-2025-12763 [HIGH] CWE-78 CVE-2025-12763: pgAdmin 4 versions up to 9.9 are affected by a command injection vulnerability on Windows systems. T pgAdmin 4 versions up to 9.9 are affected by a command injection vulnerability on Windows systems. This issue is caused by the use of shell=True during backup and restore operations, enabling attackers to execute arbitrary system commands by providing specially crafted file path input.
nvd
CVE-2024-4215P3HIGHCVSS 8.8fixed in 8.62024-05-02
CVE-2024-4215 [HIGH] CWE-89 CVE-2024-4215: pgAdmin <= 8.5 is affected by a multi-factor authentication bypass vulnerability. This vulnerability pgAdmin <= 8.5 is affected by a multi-factor authentication bypass vulnerability. This vulnerability allows an attacker with knowledge of a legitimate account’s username and password may authenticate to the application and perform sensitive actions within the application, such as managing files and executing SQL queries, regardless of the account’s MFA e
nvd
CVE-2026-7819P3HIGHCVSS 8.1fixed in 9.152026-05-11
CVE-2026-7819 [HIGH] CWE-61 CVE-2026-7819: Symbolic-link path traversal (CWE-61, CWE-22) in pgAdmin 4 File Manager. check_access_permission us Symbolic-link path traversal (CWE-61, CWE-22) in pgAdmin 4 File Manager. check_access_permission used os.path.abspath, which resolves '..' but does not resolve symbolic links, while the subsequent kernel write follows symlinks. An authenticated user could plant a symbolic link inside their own storage directory pointing outside it and induce pgAdmin to w
nvd
CVE-2026-17351P3CRITICALCVSS 9.0≥ 9.13, < 9.172026-07-31
CVE-2026-17351 [CRITICAL] CVE-2026-17351: The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assist The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlparse, as exactly one non-transaction-control statement before running it inside a BEGIN TRANSACTION READ ONLY wrapper. sqlparse's string-literal lexing can disagree with PostgreSQL's own parser: under standard_
nvd
CVE-2026-7818P3HIGHCVSS 7.8fixed in 9.152026-05-11
CVE-2026-7818 [HIGH] CWE-502 CVE-2026-7818: Deserialization of untrusted data (CWE-502) in pgAdmin 4 FileBackedSessionManager. The session mana Deserialization of untrusted data (CWE-502) in pgAdmin 4 FileBackedSessionManager. The session manager performed unsafe deserialization of session-file contents (using Python's standard object-serialization module) before performing any HMAC integrity check. Any file dropped into the sessions directory was deserialized unconditionally. An authenticated
nvd
CVE-2025-12765P3HIGHCVSS 7.4fixed in 9.102025-11-13
CVE-2025-12765 [HIGH] CWE-295 CVE-2025-12765: pgAdmin <= 9.9 is affected by a vulnerability in the LDAP authentication mechanism allows bypassing pgAdmin <= 9.9 is affected by a vulnerability in the LDAP authentication mechanism allows bypassing TLS certificate verification.
nvd
CVE-2026-7817P3MEDIUMCVSS 6.5≥ 9.13, < 9.152026-05-11
CVE-2026-7817 [MEDIUM] CWE-552 CVE-2026-7817: Local file inclusion (LFI) and server-side request forgery (SSRF) vulnerabilities in pgAdmin 4 LLM A Local file inclusion (LFI) and server-side request forgery (SSRF) vulnerabilities in pgAdmin 4 LLM API configuration endpoints. User-supplied api_key_file and api_url preferences were passed to the LLM provider clients without validation. An authenticated user could read arbitrary server-side files by pointing api_key_file at any path readable by the
nvd
CVE-2025-12764P3HIGHCVSS 7.5fixed in 9.102025-11-13
CVE-2025-12764 [HIGH] CWE-90 CVE-2025-12764: pgAdmin <= 9.9 is affected by an LDAP injection vulnerability in the LDAP authentication flow that pgAdmin <= 9.9 is affected by an LDAP injection vulnerability in the LDAP authentication flow that allows an attacker to inject special LDAP characters in the username, causing the DC/LDAP server and the client to process an unusual amount of data DOS.
nvd
CVE-2023-0241P3MEDIUMCVSS 6.5fixed in 6.19vpgadmin 6.192023-03-27
CVE-2023-0241 [MEDIUM] CWE-22 CVE-2023-0241: pgAdmin 4 versions prior to v6.19 contains a directory traversal vulnerability. A user of the produc pgAdmin 4 versions prior to v6.19 contains a directory traversal vulnerability. A user of the product may change another user's settings or alter the database.
nvd
CVE-2026-1707P3MEDIUMCVSS 6.3v9.112026-02-05
CVE-2026-1707 [MEDIUM] CWE-284 CVE-2026-1707: pgAdmin versions 9.11 are affected by a Restore restriction bypass via key disclosure vulnerability pgAdmin versions 9.11 are affected by a Restore restriction bypass via key disclosure vulnerability that occurs when running in server mode and performing restores from PLAIN-format dump files. An attacker with access to the pgAdmin web interface can observe an active restore operation, extract the `\restrict` key in real time, and race the restore pro
nvd
CVE-2025-9636P3HIGHCVSS 7.9≤ 9.72025-09-04
CVE-2025-9636 [HIGH] CWE-346 CVE-2025-9636: pgAdmin <= 9.7 is affected by a Cross-Origin Opener Policy (COOP) vulnerability. This vulnerability pgAdmin <= 9.7 is affected by a Cross-Origin Opener Policy (COOP) vulnerability. This vulnerability allows an attacker to manipulate the OAuth flow, potentially leading to unauthorised account access, account takeover, data breaches, and privilege escalation.
nvd
CVE-2026-86862P3MEDIUMCVSS 6.5fixed in 9.182026-09-17
CVE-2026-86862 [MEDIUM] CWE-88 CVE-2026-86862: pgAdmin 4's Restore and Maintenance tools passed the client-supplied 'database' field directly as th pgAdmin 4's Restore and Maintenance tools passed the client-supplied 'database' field directly as the value of the --dbname option given to pg_restore and psql. libpq expands a database name containing an equals sign into a full connection string, and connection keywords embedded in that value take precedence over the --host and --port arguments that
nvd
CVE-2026-7820P3MEDIUMCVSS 6.5fixed in 9.152026-05-11
CVE-2026-7820 [MEDIUM] CWE-307 CVE-2026-7820: Improper restriction of excessive authentication attempts (CWE-307) in pgAdmin 4. pgAdmin enforces Improper restriction of excessive authentication attempts (CWE-307) in pgAdmin 4. pgAdmin enforces MAX_LOGIN_ATTEMPTS only inside its custom /authenticate/login view. Flask-Security's default /login view, which is registered automatically by security.init_app() and is reachable on every server, never consulted the User.locked field: pgAdmin's User mode
nvd
CVE-2026-17348P3MEDIUMCVSS 6.5≥ 1.0, < 9.172026-07-31
CVE-2026-17348 [MEDIUM] CVE-2026-17348: In SERVER mode, pgAdmin 4 enforces authentication per route via the @pga_login_required decorator; t In SERVER mode, pgAdmin 4 enforces authentication per route via the @pga_login_required decorator; the application's before_request hook only handles desktop-mode auto-login and the Kerberos/Webserver-auth redirect, so any route shipped without the decorator is reachable without authentication (CWE-306). This is the same defect class previously fixed as CVE
nvd
CVE-2026-86861P3MEDIUMCVSS 5.9fixed in 9.182026-09-17
CVE-2026-86861 [MEDIUM] CVE-2026-86861: pgAdmin 4's File Manager save_file endpoint, which backs saving from the Query Tool and ERD, validat pgAdmin 4's File Manager save_file endpoint, which backs saving from the Query Tool and ERD, validated the requested path with Filemanager.check_access_permission() and then opened the file for writing with a plain open() call. CVE-2026-7819 had previously hardened the separate file upload path by opening its target with O_NOFOLLOW, so that the kernel refus
nvd
CVE-2022-0959P3MEDIUMCVSS 6.5fixed in 6.7vpgadmin 6.72022-03-16
CVE-2022-0959 [MEDIUM] CWE-434 CVE-2022-0959: A malicious, but authorised and authenticated user can construct an HTTP request using their existin A malicious, but authorised and authenticated user can construct an HTTP request using their existing CSRF token and session cookie to manually upload files to any location that the operating system user account under which pgAdmin is running has permission to write.
nvd
CVE-2026-17350P4MEDIUMCVSS 5.4≥ 9.3, < 9.172026-07-31
CVE-2026-17350 [MEDIUM] CWE-862 CVE-2026-17350: The per-tool permission system (custom roles / role-based tool permissions, introduced in pgAdmin 4 The per-tool permission system (custom roles / role-based tool permissions, introduced in pgAdmin 4 9.3) did not enforce its permission check consistently. In SERVER mode, pgAdmin 4 gates each tool behind a per-tool Flask-Security permission, but the permission decorator (permissions_required) was applied only to a single "front door" route per tool.
nvd
CVE-2026-12049P4MEDIUMCVSS 6.1≥ 6.0, < 9.162026-06-19
CVE-2026-12049 [MEDIUM] CWE-601 CVE-2026-12049: Open redirect in pgAdmin 4's multi-factor authentication flow. The MFA validate and register endpoin Open redirect in pgAdmin 4's multi-factor authentication flow. The MFA validate and register endpoints honoured the user-supplied 'next' query/form parameter without confirming the target pointed back inside pgAdmin, so an authenticated victim who clicked /mfa/validate?next= -- a link typically delivered by phishing -- would be sent to an attacker-c
nvd
CVE-2026-12048P4MEDIUMCVSS 5.4≥ 6.0, < 9.162026-06-19
CVE-2026-12048 [MEDIUM] CWE-79 CVE-2026-12048: Stored cross-site scripting in pgAdmin 4's error-rendering and plan-node-rendering paths. Text retur Stored cross-site scripting in pgAdmin 4's error-rendering and plan-node-rendering paths. Text returned by a PostgreSQL server (ErrorResponse messages, including object names quoted back inside relation-does-not-exist errors and inside EXPLAIN Recheck Cond / Exact Heap Blocks fields) was passed verbatim through html-react-parser at every user-facing
nvd
Pgadmin 4 vulnerabilities | cvebase