PT-2026-39629 · Pgadmin 4+2 · Pgadmin 4+2

·

CVE-2026-7819

·

Published

2026-05-01

·

Updated

2026-08-13

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:S/C:N/I:C/A:C
Name of the Vulnerable Software and Affected Versions pgAdmin 4 versions prior to 9.15
Description A symbolic-link path traversal issue exists in the pgAdmin 4 File Manager. The check access permission() function utilized os.path.abspath, which resolves parent directory references but fails to resolve symbolic links. Because the subsequent kernel write operation follows symbolic links, an authenticated user can create a symbolic link within their own storage directory that points to an external location. This allows the user to induce pgAdmin to write to any path accessible by the pgAdmin process, potentially compromising the integrity and availability of protected information. This is a TOCTOU (Time-of-Check to Time-of-Use) race condition between the access check and the file open operation.
Recommendations Update to version 9.15 or later.

Exploit

Fix

DoS

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09125
CVE-2026-7819
GHSA-HR4R-FWPV-C95J
OPENSUSE-SU-2026:11508-1
PYSEC-2026-2868

Affected Products

Pgadmin
Red Os
Pgadmin 4