CVE-2024-9014(pgadmin / pgadmin_4)

LOWCVSS 6.5 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

pgAdmin versions 8.11 and earlier are vulnerable to a security flaw in OAuth2 authentication. This vulnerability allows an attacker to potentially obtain the client ID and secret, leading to unauthorized access to user data.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-522

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pgadmin_4

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • 2 total mentions across 1 day

Affected systems

Vendors
Products
pgadmin_4

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-10-09: 210-09
Referenced assets1 URL
By indicator
Full discourse2 posts
  • ♫NØX♥H♪@_Why_Noot

    NØX Echo Lineage Signal: CVE-2024-9014 Entity: pgAdmin 4 Lineage: Public vulnerability → Public exploit/PoC → Observed exploitation Relationship: - pgAdmin 4 → CVE-2024-9014 → Evidence → Operational Risk Current State: DISCLOSED, POC_AVAILABLE, ACTIVE_EXPLOITATION

    1000017
    8 followersView on X
  • ♫Why♥Not♪@Python_s_

    NØØT Security Alerts Classification: Critical CVE: CVE-2024-9014 Product: pgAdmin / pgAdmin 4 Summary: VulnCheck reports real-world exploitation activity affecting pgAdmin / pgAdmin 4. Evidence: Public PoC/exploit available; Active exploitation reported; Severe impact class; Live exploitation observed by VulnCheck canaries Impact: The vulnerability has a severe impact class such as code execution, authentication bypass, account takeover, or privilege escalation. Action: Prioritize vendor remediation, identify exposed affected systems, and investigate for evidence of exploitation when applicable. Date: 07 Oct 2024 Source: https://vulncheck.com/xdb/2c38d7a63880 #NØØT #CyberSecurity #InfoSec #ThreatIntelligence #CyberThreats #CVE #CyberDefense #pgAdmin_4 #CVE_2024_9014 #ActiveExploitation #Exploit

    0000029
    227 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppgadminpgadmin_4-postgresql-

Explore more