PT-2026-66774 · Pgadmin 4+1 · Pgadmin 4+1

CVE-2026-17349

·

Published

2026-07-31

·

Updated

2026-08-13

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions pgAdmin 4 versions 9.0 through 9.16
Description The /misc/workspace/adhoc connect server endpoint, part of the Workspaces feature, improperly clones server records using the Server.clone() function. When a non-owner triggers an adhoc connection to another user's shared server, the system copies all columns from the source row, including user id, shared, shared username, and credential fields such as password, save password, and tunnel password. This allows a non-owner to inherit the ownership and stored database credentials of the source user, typically an administrator. Because the record is persisted before the connection attempt, the non-owner can subsequently use the cloned server to connect to the database using the source user's privileges.
Recommendations Update pgAdmin 4 to version 9.17 or later.

Exploit

Fix

DoS

Insufficiently Protected Credentials

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-17349
OPENSUSE-SU-2026:11508-1

Affected Products

Pgadmin
Pgadmin 4