PT-2026-6603 · Pgadmin+1 · Pgadmin+1

·

CVE-2026-1707

·

Published

2026-02-05

·

Updated

2026-08-13

CVSS v3.1

7.4

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions pgAdmin version 9.11
Description pgAdmin version 9.11 is susceptible to a restriction bypass issue during restore operations when running in server mode and processing PLAIN-format dump files. An attacker with access to the pgAdmin web interface can potentially extract the restrict key during an active restore operation. This allows the attacker to race the restore process by overwriting the restore script with a payload that re-enables meta-commands using unrestrict <key>, leading to potential command execution on the pgAdmin host during the restore operation. The vulnerable operation involves restoring from PLAIN-format dump files.
Recommendations Apply a fix or update to a version newer than 9.11. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Information Disclosure

IDOR

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-02533
CVE-2026-1707
GHSA-3P7X-94Q9-JQ9X
OPENSUSE-SU-2026:11508-1
PYSEC-2026-2864

Affected Products

Pgadmin
Red Os