PT-2026-50815 · Pgadmin 4+1 · Pgadmin 4+1

·

CVE-2026-12049

·

Published

2026-06-18

·

Updated

2026-08-13

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions pgAdmin 4 versions 6.0 through 9.15
Description An open redirect exists in the multi-factor authentication (MFA) flow. The MFA validate and register endpoints, specifically '/mfa/validate', process the user-supplied next query or form parameter without verifying if the target destination is internal to the application. This allows an authenticated user to be redirected to an attacker-controlled host after clicking a malicious link, which can be used to increase the effectiveness of credential-phishing attacks by making the destination appear to originate from a trusted domain. This issue does not grant the attacker read or write access to the application or the database.
Recommendations Update to version 9.16.

Exploit

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12049
OPENSUSE-SU-2026:11508-1

Affected Products

Pgadmin
Pgadmin 4