PT-2026-39625 · Postgresql Global Development Group+3 · Postgresql+3

·

CVE-2026-7815

·

Published

2026-05-01

·

Updated

2026-07-28

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions pgAdmin 4 versions prior to 9.15
Description An SQL injection exists in the Maintenance Tool where four user-supplied JSON fields—buffer usage limit, vacuum parallel, vacuum index cleanup, and reindex tablespace—are concatenated directly into the rendered VACUUM, ANALYZE, or REINDEX command and passed to psql --command. An authenticated user with the tools maintenance permission can break out of the option syntax to execute arbitrary SQL on the connected PostgreSQL server. This can further lead to operating-system command execution on the database host by invoking the COPY ... TO PROGRAM command.
Recommendations Update to version 9.15 or later.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09129
CVE-2026-7815
GHSA-HP84-P2GQ-6FVR
PYSEC-2026-2867

Affected Products

Pgadmin
Postgresql
Red Os
Pgadmin 4