PT-2026-39628 · Pgadmin 4+1 · Pgadmin 4+1
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
pgAdmin 4 versions prior to 9.15
Description
The
FileBackedSessionManager in pgAdmin 4 performs unsafe deserialization of session-file contents using Python's standard object-serialization module before conducting an HMAC integrity check. This allows any file placed in the sessions directory to be deserialized unconditionally. An authenticated user with write access to the sessions directory, potentially through misconfiguration or a path-traversal flaw, can use a crafted serialized payload to achieve operating-system level remote code execution under the pgAdmin process identity.Recommendations
Update to version 9.15 or later.
Restrict write access to the sessions directory to prevent unauthorized users from planting crafted files.
Exploit
Fix
DoS
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pgadmin
Pgadmin 4