{
  "threat_severity" : "Moderate",
  "public_date" : "2026-07-31T15:59:18Z",
  "bugzilla" : {
    "description" : "pgadmin4: pgAdmin 4: Unauthenticated access allows data manipulation and information disclosure",
    "id" : "2509842",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2509842"
  },
  "cvss3" : {
    "cvss3_base_score" : "6.5",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L",
    "status" : "draft"
  },
  "cwe" : "CWE-306",
  "details" : [ "In SERVER mode, pgAdmin 4 enforces authentication per route via the @pga_login_required decorator; the application's before_request hook only handles desktop-mode auto-login and the Kerberos/Webserver-auth redirect, so any route shipped without the decorator is reachable without authentication (CWE-306). This is the same defect class previously fixed as CVE-2026-12046 (the sqleditor close/update_connection routes).\nA follow-up sweep, prompted by a report describing an incomplete fix for CVE-2026-12046, found further routes missing @pga_login_required: the Constraints blueprint's nodes and proplist (object listing) routes and its delete route (a state-mutating DELETE that removes table constraints); preferences.get_all_cli (GET, discloses all CLI-settable preference values); debugger.close (DELETE); and schema_diff.close (DELETE). An unauthenticated network client could therefore enumerate constraint metadata, delete table constraints, read preference values, and force-close debugger or schema-diff sessions belonging to other users, without ever authenticating.\nFix adds the missing @pga_login_required decorator (and the corresponding import to the Constraints module) to each of these routes. The change is decorator-only; no behavioral changes to the underlying handlers.\nThis issue affects pgAdmin 4 in SERVER mode: the Constraints and Debugger routes from 1.0, the Schema Diff close route from 4.18, and preferences.get_all_cli from 8.2, all before 9.17.", "A flaw was found in pgAdmin 4. In SERVER mode, an unauthenticated network client could exploit missing authentication controls on specific routes. This vulnerability allows an attacker to enumerate constraint metadata, read sensitive preference values, delete table constraints, and force-close debugger or schema-diff sessions belonging to other users. This could lead to unauthorized data modification, information disclosure, and denial of service for legitimate users." ],
  "statement" : "This package is not shipped in any Red Hat products, only the Fedora community project.",
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-17348\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-17348\nhttps://github.com/pgadmin-org/pgadmin4/commit/24fdcf0f58591c87ada31366c01e1af180eceb05\nhttps://github.com/pgadmin-org/pgadmin4/issues/10194" ],
  "name" : "CVE-2026-17348",
  "csaw" : false
}