PT-2024-6396 · Pgadmin+1 · Pgadmin+1

CVE-2024-9014

·

Published

2024-09-23

·

Updated

2026-07-07

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions pgAdmin versions 8.11 and earlier
Description The issue is related to a security flaw in OAuth2 authentication, allowing an attacker to potentially obtain the client ID and secret, leading to unauthorized access to user data. The vulnerability is associated with insufficient protection of registration data.
Recommendations For pgAdmin versions 8.11 and earlier, consider disabling OAuth2 authentication until a patch is available. Restrict access to sensitive data to minimize the risk of exploitation. Avoid using the client id and client secret parameters in the affected OAuth2 authentication flow until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-07481
CVE-2024-9014
GHSA-JM9X-RX9X-WPQJ
OPENSUSE-SU-2024_3771-1
OPENSUSE-SU-2025:14983-1
PYSEC-2026-1775
SUSE-SU-2024:3771-1

Affected Products

Pgadmin
Suse