CVE-2026-12046

Description

A flaw was found in pgAdmin 4. Critical functions within the SQL Editor blueprint lacked proper authentication, allowing a remote attacker to bypass security controls. When combined with specific preconditions, such as knowledge of the Flask SECRET_KEY and write access to the sessions directory, this vulnerability could enable unauthenticated remote code execution on the server. This issue primarily affects pgAdmin 4 deployments in server mode.

Statement

This is an Important flaw in pgAdmin 4, as it could lead to unauthenticated remote code execution on the server. However, successful exploitation requires an attacker to already possess the Flask SECRET_KEY and have write access to the pgAdmin sessions directory, which significantly raises the bar for exploitation and implies a prior compromise or misconfiguration. This vulnerability is specific to pgAdmin 4 deployments operating in server mode.

Mitigation

To mitigate the risk, restrict network access to the pgAdmin 4 server. Configure firewall rules to allow connections only from trusted internal networks or localhost. For example, using `firewalld` on Red Hat Enterprise Linux, administrators can limit inbound traffic to the pgAdmin 4 listening port. This action may affect remote access to the pgAdmin 4 interface.

Understanding the Weakness (CWE)

Access Control,Other

Technical Impact: Gain Privileges or Assume Identity; Varies by Context

Exposing critical functionality essentially provides an attacker with the privilege level of that functionality. The consequences will depend on the associated functionality, but they can range from reading or modifying sensitive data, accessing administrative or other privileged functionality, or possibly even executing arbitrary code.

Frequently Asked Questions

Want to get errata notifications? Sign up here.