CVE-2026-17350
Description
A flaw was found in pgAdmin 4. In SERVER mode, an authenticated user who has been explicitly denied access to a specific tool by an administrator could still bypass this restriction. This is due to inconsistent enforcement of the per-tool permission system, where backend routes and Socket.IO handlers did not properly check tool-specific permissions. This allows the user to access and utilize features, such as an interactive psql session or backup/restore jobs, that an administrator intended to withhold, thereby circumventing pgAdmin's access control policy.
Statement
This flaw affects only the Fedora community project; no Red Hat products are affected.
Understanding the Weakness (CWE)
Confidentiality,Integrity,Availability,Access Control
Technical Impact: Read Application Data; Modify Application Data; Execute Unauthorized Code or Commands; Gain Privileges or Assume Identity
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.