PT-2026-66774 · Pgadmin 4+1 · Pgadmin 4+1
CVE-2026-17349
·
Published
2026-07-31
·
Updated
2026-08-13
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
pgAdmin 4 versions 9.0 through 9.16
Description
The
/misc/workspace/adhoc connect server endpoint, part of the Workspaces feature, improperly clones server records using the Server.clone() function. When a non-owner triggers an adhoc connection to another user's shared server, the system copies all columns from the source row, including user id, shared, shared username, and credential fields such as password, save password, and tunnel password. This allows a non-owner to inherit the ownership and stored database credentials of the source user, typically an administrator. Because the record is persisted before the connection attempt, the non-owner can subsequently use the cloned server to connect to the database using the source user's privileges.Recommendations
Update pgAdmin 4 to version 9.17 or later.
Exploit
Fix
DoS
Insufficiently Protected Credentials
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pgadmin
Pgadmin 4