pgadmin.org pgAdmin
4 known vulnerabilities in pgadmin.org pgAdmin, 1 critical, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-86864 CVSS 8.7 high pgAdmin 4's Backup tool appended the client-supplied 'database' field from the /backup/job/<sid>/object request to the pg_dump argument…
- CVE-2026-86863 CVSS 9.3 critical pgAdmin 4's Webserver authentication source is intended to accept an identity asserted by the web server or reverse proxy in front of…
- CVE-2026-86862 CVSS 7.1 high pgAdmin 4's Restore and Maintenance tools passed the client-supplied 'database' field directly as the value of the --dbname option given…
- CVE-2026-86861 CVSS 6.0 medium pgAdmin 4's File Manager save_file endpoint, which backs saving from the Query Tool and ERD, validated the requested path with…