Pgadmin
Pgadmin 4: vulnerabilidades y CVE
Pgadmin 4 tiene 46 vulnerabilidades publicadas, 32 de ellas en los últimos 12 meses. 11 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE46
Últimos 12 meses32
Críticas11
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-86864 | Alta (8.7) | 0.58% | — | 17 sept 2026 | pgAdmin 4's Backup tool appended the client-supplied 'database' field from the /backup/job/<sid>/object request to the pg_dump argument vector as a bare trailing positional argument, without validation. Because pg_dump… |
| CVE-2026-86863 | Crítica (9.3) | 0.58% | — | 17 sept 2026 | pgAdmin 4's Webserver authentication source is intended to accept an identity asserted by the web server or reverse proxy in front of pgAdmin, delivered through the WSGI/CGI environment.… |
| CVE-2026-86862 | Alta (7.1) | 0.35% | — | 17 sept 2026 | pgAdmin 4's Restore and Maintenance tools passed the client-supplied 'database' field directly as the value of the --dbname option given to pg_restore and psql. libpq expands a database name containing an equals sign… |
| CVE-2026-86861 | Media (6) | 0.32% | — | 17 sept 2026 | pgAdmin 4's File Manager save_file endpoint, which backs saving from the Query Tool and ERD, validated the requested path with Filemanager.check_access_permission() and then opened the file for writing with a plain… |
| CVE-2026-17566 | Crítica (9.4) | 0.67% | — | 31 jul 2026 | pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-supplied SQL query into a Jinja template and passing the rendered line to psql via --command. To stop an attacker from… |
| CVE-2026-17351 | Crítica (9.4) | 0.48% | — | 31 jul 2026 | The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlparse, as exactly one non-transaction-control statement before running it… |
| CVE-2026-17350 | Media (5.3) | 0.38% | — | 31 jul 2026 | The per-tool permission system (custom roles / role-based tool permissions, introduced in pgAdmin 4 9.3) did not enforce its permission check consistently. In SERVER mode, pgAdmin 4 gates each tool behind a per-tool… |
| CVE-2026-17349 | Crítica (9.3) | 0.40% | — | 31 jul 2026 | /misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, when passed the id of an existing server, clones that server via Server.clone(), which copies every column from the… |
| CVE-2026-17348 | Media (6.9) | 0.42% | — | 31 jul 2026 | In SERVER mode, pgAdmin 4 enforces authentication per route via the @pga_login_required decorator; the application's before_request hook only handles desktop-mode auto-login and the Kerberos/Webserver-auth redirect, so… |
| CVE-2026-17347 | Alta (7.7) | 0.72% | — | 31 jul 2026 | The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an external command that returns a per-user encryption key, with %u in the configured string replaced by the current user's… |
| CVE-2026-17346 | Alta (8.7) | 0.61% | — | 31 jul 2026 | The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT ON / pgstattuple / pgstatindex templates to it, but missed several sinks that had been placed in… |
| CVE-2026-12050 | Media (5.3) | 0.43% | — | 19 jun 2026 | SQL injection in pgAdmin 4's named restore point endpoint (POST /browser/server/restore_point/{gid}/{sid}). The user-supplied 'value' field was interpolated directly into the SQL string with str.format() instead of… |
| CVE-2026-12049 | Media (5.3) | 0.38% | — | 19 jun 2026 | Open redirect in pgAdmin 4's multi-factor authentication flow. The MFA validate and register endpoints honoured the user-supplied 'next' query/form parameter without confirming the target pointed back inside pgAdmin, so… |
| CVE-2026-12048 | Crítica (9.3) | 0.27% | — | 19 jun 2026 | Stored cross-site scripting in pgAdmin 4's error-rendering and plan-node-rendering paths. Text returned by a PostgreSQL server (ErrorResponse messages, including object names quoted back inside relation-does-not-exist… |
| CVE-2026-12047 | Media (4.8) | 0.22% | — | 19 jun 2026 | HTML injection in pgAdmin 4's cloud deployment module. The verify_credentials, deploy, regions, and update-server endpoints under /rds/, /azure/, /google/, and the top-level /cloud/ blueprint propagated AWS / Azure /… |
| CVE-2026-12046 | Crítica (9.5) | 1.0% | — | 19 jun 2026 | Two state-mutating endpoints in pgAdmin 4's SQL Editor blueprint -- DELETE /sqleditor/close/<trans_id> and POST /sqleditor/initialize/sqleditor/update_connection/<sgid>/<sid>/<did> -- were the only routes in the module… |
| CVE-2026-12045 | Crítica (9.4) | 0.66% | — | 19 jun 2026 | Read-only transaction bypass in the pgAdmin 4 AI Assistant allows an attacker who can influence database content that the assistant reads to execute arbitrary SQL with the privileges of the pgAdmin user's database role.… |
| CVE-2026-12044 | Alta (8.7) | 0.71% | — | 19 jun 2026 | SQL injection in pgAdmin 4 across every dialog template that renders ``COMMENT ON ... IS '<description>'`` for a user-supplied description field. The Jinja templates for Domains (and their constraints), Foreign Tables,… |
| CVE-2026-7820 | Media (6.9) | 0.33% | — | 11 may 2026 | Improper restriction of excessive authentication attempts (CWE-307) in pgAdmin 4. pgAdmin enforces MAX_LOGIN_ATTEMPTS only inside its custom /authenticate/login view. Flask-Security's default /login view, which is… |
| CVE-2026-7819 | Alta (7.2) | 0.48% | — | 11 may 2026 | Symbolic-link path traversal (CWE-61, CWE-22) in pgAdmin 4 File Manager. check_access_permission used os.path.abspath, which resolves '..' but does not resolve symbolic links, while the subsequent kernel write follows… |
| CVE-2026-7818 | Alta (7.3) | 0.35% | — | 11 may 2026 | Deserialization of untrusted data (CWE-502) in pgAdmin 4 FileBackedSessionManager. The session manager performed unsafe deserialization of session-file contents (using Python's standard object-serialization module)… |
| CVE-2026-7817 | Alta (7.1) | 0.35% | — | 11 may 2026 | Local file inclusion (LFI) and server-side request forgery (SSRF) vulnerabilities in pgAdmin 4 LLM API configuration endpoints. User-supplied api_key_file and api_url preferences were passed to the LLM provider clients… |
| CVE-2026-7816 | Alta (8.7) | 2.2% | — | 11 may 2026 | OS command injection (CWE-78) vulnerability in pgAdmin 4 Import/Export query export. User-supplied input was interpolated directly into a psql \copy metacommand template without sanitization. An authenticated user could… |
| CVE-2026-7815 | Alta (8.7) | 0.64% | — | 11 may 2026 | SQL injection vulnerability in pgAdmin 4 Maintenance Tool. Four user-supplied JSON fields (buffer_usage_limit, vacuum_parallel, vacuum_index_cleanup, reindex_tablespace) were concatenated directly into the rendered… |
| CVE-2026-7814 | Media (4.8) | 0.25% | — | 11 may 2026 | Stored cross-site scripting (XSS) vulnerability in pgAdmin 4 Browser Tree and Explain Visualizer modules. User-controlled PostgreSQL object names (database, schema, table, column, etc.) were assigned to DOM elements via… |
| CVE-2026-7813 | Crítica (9.4) | 0.65% | — | 11 may 2026 | Authorization vulnerability in pgAdmin 4 server mode affecting Server Groups, Servers, Shared Servers, Background Processes, and Debugger modules. Multiple endpoints fetched user-owned objects without filtering by the… |
| CVE-2026-1707 | Media (6.3) | 0.42% | — | 5 feb 2026 | pgAdmin versions 9.11 are affected by a Restore restriction bypass via key disclosure vulnerability that occurs when running in server mode and performing restores from PLAIN-format dump files. An attacker with access… |
| CVE-2025-13780 | Alta (8.8) | 0.94% | — | 11 dic 2025 | pgAdmin versions up to 9.10 are affected by a Remote Code Execution (RCE) vulnerability that occurs when running in server mode and performing restores from PLAIN-format dump files. This issue allows attackers to inject… |
| CVE-2025-12763 | Alta (8.8) | 0.94% | — | 13 nov 2025 | pgAdmin 4 versions up to 9.9 are affected by a command injection vulnerability on Windows systems. This issue is caused by the use of shell=True during backup and restore operations, enabling attackers to execute… |
| CVE-2025-12762 | Crítica (9.8) | 13% | — | 13 nov 2025 | pgAdmin versions up to 9.9 are affected by a Remote Code Execution (RCE) vulnerability that occurs when running in server mode and performing restores from PLAIN-format dump files. This issue allows attackers to inject… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.