PT-2026-94390 · Pgadmin 4+1 · Pgadmin 4+1

·

CVE-2026-86863

·

Published

2026-09-17

·

Updated

2026-09-24

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions pgAdmin 4 versions 6.2 through 9.17
Description An authentication bypass exists when the 'webserver' source is enabled in AUTHENTICATION SOURCES. The WebserverAuthentication.get user() function reads the config.WEBSERVER REMOTE USER from the environment and, if empty, falls back to reading the same name directly from inbound HTTP request headers via request.headers.get(). Because HTTP headers are client-controlled, an attacker can supply a specific header to be authenticated as any user, including an Administrator, without providing a password. This also occurs if WEBSERVER REMOTE USER is configured with an HTTP-prefixed or hyphenated name, as WSGI servers place inbound headers into the environment using those formats.
Recommendations Update pgAdmin 4 to version 9.18 or later. As a temporary mitigation, disable 'webserver' in AUTHENTICATION SOURCES if it is not required.

Exploit

Fix

Authentication Bypass by Spoofing

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-86863

Affected Products

Pgadmin
Pgadmin 4