Pgadmin 4 · Pgadmin 4 · CVE-2026-86863
**Name of the Vulnerable Software and Affected Versions**
pgAdmin 4 versions 6.2 through 9.17
**Description**
An authentication bypass exists when the 'webserver' source is enabled in `AUTHENTICATION SOURCES`. The `WebserverAuthentication.get user()` function reads the `config.WEBSERVER REMOTE USER` from the environment and, if empty, falls back to reading the same name directly from inbound HTTP request headers via `request.headers.get()`. Because HTTP headers are client-controlled, an attacker can supply a specific header to be authenticated as any user, including an Administrator, without providing a password. This also occurs if `WEBSERVER REMOTE USER` is configured with an HTTP-prefixed or hyphenated name, as WSGI servers place inbound headers into the environment using those formats.
**Recommendations**
Update pgAdmin 4 to version 9.18 or later.
As a temporary mitigation, disable 'webserver' in `AUTHENTICATION SOURCES` if it is not required.