PT-2026-39625 · Pgadmin 4+2 · Pgadmin 4+2

J3Seer

·

Published

2026-05-11

·

Updated

2026-05-26

·

CVE-2026-7815

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions pgAdmin 4 versions prior to 9.15
Description An SQL injection exists in the Maintenance Tool where four user-supplied JSON fields—buffer usage limit, vacuum parallel, vacuum index cleanup, and reindex tablespace—are concatenated directly into the rendered VACUUM, ANALYZE, or REINDEX command and passed to psql --command. An authenticated user with the tools maintenance permission can break out of the option syntax to execute arbitrary SQL on the connected PostgreSQL server. This can further lead to operating-system command execution on the database host by invoking the COPY ... TO PROGRAM command.
Recommendations Update to version 9.15 or later.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-7815
GHSA-HP84-P2GQ-6FVR

Affected Products

Pgadmin
Postgresql
Pgadmin 4