PT-2026-6603 · Pgadmin · Pgadmin
Akshay-Joshi
·
Published
2026-02-05
·
Updated
2026-02-06
·
CVE-2026-1707
CVSS v3.1
7.4
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
pgAdmin version 9.11
Description
pgAdmin version 9.11 is susceptible to a restriction bypass issue during restore operations when running in server mode and processing PLAIN-format dump files. An attacker with access to the pgAdmin web interface can potentially extract the
restrict key during an active restore operation. This allows the attacker to race the restore process by overwriting the restore script with a payload that re-enables meta-commands using unrestrict <key>, leading to potential command execution on the pgAdmin host during the restore operation. The vulnerable operation involves restoring from PLAIN-format dump files.Recommendations
Apply a fix or update to a version newer than 9.11. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
IDOR
Improper Access Control
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pgadmin