PT-2026-39626 · Pgadmin 4+2 · Pgadmin 4+2

·

CVE-2026-7816

·

Published

2026-05-01

·

Updated

2026-08-13

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions pgAdmin 4 versions prior to 9.15
Description An OS command injection issue exists in the Import/Export query export feature. Authenticated users can exploit this by providing unsanitized input that is interpolated directly into a psql copy metacommand template. This allows an attacker to break out of the command context to execute arbitrary commands on the pgAdmin server or perform arbitrary file writes. Additionally, the format, on error, and log verbosity fields are susceptible to raw interpolation and exploitation.
Recommendations Update to version 9.15 or later. Restrict access to the Import/Export query export feature for authenticated users until the update is applied.

Exploit

Fix

SQL injection

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09123
CVE-2026-7816
GHSA-J74F-G7VX-FH4X
OPENSUSE-SU-2026:11508-1
PYSEC-2026-2870

Affected Products

Pgadmin
Red Os
Pgadmin 4