PT-2026-94390 · Pgadmin 4+1 · Pgadmin 4+1
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
pgAdmin 4 versions 6.2 through 9.17
Description
An authentication bypass exists when the 'webserver' source is enabled in
AUTHENTICATION SOURCES. The WebserverAuthentication.get user() function reads the config.WEBSERVER REMOTE USER from the environment and, if empty, falls back to reading the same name directly from inbound HTTP request headers via request.headers.get(). Because HTTP headers are client-controlled, an attacker can supply a specific header to be authenticated as any user, including an Administrator, without providing a password. This also occurs if WEBSERVER REMOTE USER is configured with an HTTP-prefixed or hyphenated name, as WSGI servers place inbound headers into the environment using those formats.Recommendations
Update pgAdmin 4 to version 9.18 or later.
As a temporary mitigation, disable 'webserver' in
AUTHENTICATION SOURCES if it is not required.Exploit
Fix
Authentication Bypass by Spoofing
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pgadmin
Pgadmin 4