CVE-2026-86864

Description

A flaw was found in pgAdmin 4. An authenticated user with 'tools_backup' permission can exploit an argument injection vulnerability in the Backup tool to create or overwrite arbitrary files on the system where pgAdmin is running. Additionally, a connection-string injection vulnerability allows the user to redirect database connections to an attacker-controlled server, potentially disclosing stored database credentials. This can lead to data destruction, system compromise or unauthorized access to sensitive information.

Statement

Red Hat Product Security has determined that this vulnerability does not affect any currently supported Red Hat product. This assessment may evolve based on further analysis and discovery. For more information about this vulnerability and the products it affects, please see the linked references.

Understanding the Weakness (CWE)

Confidentiality,Integrity,Availability,Other

Technical Impact: Execute Unauthorized Code or Commands; Alter Execution Logic; Read Application Data; Modify Application Data

An attacker could include arguments that allow unintended commands or code to be executed, allow sensitive data to be read or modified or could cause other unintended behavior.

Frequently Asked Questions

Want to get errata notifications? Sign up here.