PT-2026-94391 · Pgadmin · Pgadmin

·

CVE-2026-86864

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions pgAdmin 4 versions prior to 9.18
Description The Backup tool in pgAdmin 4 fails to validate the database field within the /backup/job/<sid>/object endpoint. This field is appended as a positional argument to the pg dump utility. Since pg dump uses getopt long for argument parsing, an attacker can provide a value starting with a dash to inject options. For example, using --file=/absolute/path allows the utility to write output to arbitrary locations accessible by the pgAdmin process, enabling arbitrary file creation and overwrite. Additionally, the database field allows connection-string injection because libpq expands names containing equals signs into full connection strings. This allows an attacker to redirect pg dump to a remote server, potentially leaking the decrypted database password stored in the PGPASSWORD environment variable. These actions can be performed by any authenticated user with tools backup permissions.
Recommendations Update pgAdmin 4 to version 9.18 or later.

Exploit

Fix

DoS

Path traversal

Argument Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-86864

Affected Products

Pgadmin