CVE-2026-12046Patch

LOW

Exploit discussion active in current signal (6 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

2.0/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 7 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 7 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked at 6 mentions on most recent observed day (2026-06-22)
  • 7 total mentions across 2 days

Deep dive

Activity timeline7 mentions / 2d
02356Mentions · 2026-06-19: 1Mentions · 2026-06-22: 6PoC Mentioned / Linked · 2026-06-22: 1Patch / Workaround · 2026-06-19: 1Patch / Workaround · 2026-06-22: 4Technical Details · 2026-06-19: 1Technical Details · 2026-06-22: 606-1906-22
Signal classification3 categories
Patch
457.1%
Disclosure
228.6%
General
114.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-06-191
Disclosure1
2026-06-226
Disclosure1General1Patch4
Full discourse7 posts
  • FOFA@fofabot
    General

    ⚠️⚠️ CVE-2026-12046 (CVSS 9.5) + CVE-2026-12045 + CVE-2026-12048 (CVSS 9.3): pgAdmin 4 server-mode flaws enable unauth RCE and stored XSS in PostgreSQL admin UI. 🔗FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJwZ0FkbWluNCI= 🎯66.4K+ Results are found on http://en.fofa.info in the past year. FOFA Query: app="pgAdmin4" 🔖Refer: https://securityonline.info/pgadmin-4-vulnerabilities/ #OSINT #FOFA #CyberSecurity #Vulnerability

    Post summary

    The post alerts to three pgAdmin 4 vulnerabilities with high CVSS scores, noting unauthenticated RCE and stored XSS, but offers no proof of exploitation, patching, or active use evidence.

    1262995842.7K
    14.6K followersView on X
  • yousukezan@yousukezan
    Patch

    PostgreSQL管理ツールpgAdmin 4で、CVSS 9.0超の重大な脆弱性3件が修正された。影響にはクロスサイトスクリプティング(XSS)、認証回避を伴うコード実行、AIアシスタント経由のSQL悪用が含まれ、バージョン9.16で対処されている。 CVE-2026-12048(CVSS 9.3)は保存型XSSで、エラーメッセージや実行計画の表示時にサニタイズされていないデータが描画される問題だった。低権限ユーザーや悪意のあるPostgreSQLサーバーがHTMLやiframeを埋め込み、pgAdmin画面内で不正コンテンツを表示できた。 CVE-2026-12046(CVSS 9.5)はSQL Editorの2つのエンドポイントで認証チェックが欠落していた問題で、サーバーモードでは未認証アクセスが可能だった。さらにセッション情報へのアクセスなど別の条件が揃うと、コード実行につながる可能性があった。 CVE-2026-12045(CVSS 9.4)はAI Assistantに存在する脆弱性で、プロンプトインジェクションを利用して読み取り専用トランザクションを終了させ、その後のSQLを自動コミットで実行できた。権限次第ではデータ改変やコマンド実行に悪用される可能性があった。 pgAdminチームはバージョン9.16で全ての問題を修正したとしている。 https://securityonline.info/pgadmin-4-vulnerabilities/

    Post summary

    pgAdmin 4 fixed three high‑score vulnerabilities (XSS, authentication bypass, AI assistant SQL injection) in version 9.16; the text provides technical details but no PoC, exploit code, or evidence of active exploitation.

    0801622.2K
    14.8K followersView on X
  • Netlas.io@Netlas_io
    Disclosure

    CVE-2026-12046: RCE vulnerability in pgAdmin 4, 9.5 rating 🔥 Two SQL Editor endpoints were missing the login-required decorator and were reachable without authentication in server mode. This exposes an unauthenticated remote code execution path in the pgAdmin process. 👉 https://nt.ls/jbYEF

    Post summary

    The tweet announces a new RCE vulnerability (CVE‑2026‑12046) in pgAdmin, gives technical details, and links to a resource that likely contains a PoC.

    140631.5K
    7.7K followersView on X
  • GovCERT.CZ@GOVCERT_CZ
    Patch

    🚨 Upozorňujeme na zranitelnosti v pgAdmin 4, CVE-2026-12046, CVE-2026-12045, CVE-2026-12048. Tyto zranitelnosti zahrnují neautentizovanou deserializaci (pickle) v routách SQL Editoru (close a update_connection), která umožňuje vzdálené spuštění kódu, zranitelnost AI Assistant Prompt Injection kombinovanou se SQL Injection a obcházením read-only transakcí, a také uložený Cross-Site Scripting prostřednictvím nedůvěryhodného textu chyb a plan-node renderovaného přes html-react-parser. Útočník může za určitých podmínek bez autentizace spustit škodlivý kód, manipulovat s databázovými dotazy, obcházet bezpečnostní omezení a injektovat skripty vedoucí ke kompromitaci uživatelských relací nebo dat. 📌Doporučujeme aktualizovat na pgAdmin verze 9.16 nebo novější.

    Post summary

    The recent pgAdmin 4 release contains three critical CVEs (CVE‑2026‑12045/12046/12048) that enable unauthenticated remote code execution, AI assistant prompt injection, and stored XSS; immediately upgrade to version 9.16 or newer to mitigate these threats.

    03020627
    4.3K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Critical vulnerabilities (#RCE + stored #XSS) in #pgAdmin 4 allow unauthenticated remote code execution and credential theft. #CVE-2026-12048 #CVE-2026-12046 #CVE-2026-12045 CVSS(3.1): 9.3/9.0. Read the advisory https://ccb.belgium.be/advisories/warning-remote-code-execution-and-cross-site-scripting-pgadmin-4-can-be-exploited and #Patch #Patch #Patch

    Post summary

    The advisory warns of critical RCE and XSS vulnerabilities in pgAdmin 4, provides CVSS scores and CVE IDs, and directs readers to apply the linked patch.

    01000388
    7.2K followersView on X
  • Daily CyberSecurity@the_yellow_fall
    Patch

    Three critical pgAdmin 4 vulnerabilities (CVE-2026-12046, CVE-2026-12048, CVE-2026-12045) risk XSS and RCE. Update to pgAdmin 4 9.16 now. #pgAdmin #PostgreSQL #XSS #RCE #CVE #Vulnerability https://securityonline.info/pgadmin-4-vulnerabilities https://t.co/msfkHZZ9l1

    Post summary

    Three critical XSS and RCE vulnerabilities were disclosed in pgAdmin 4; users are advised to upgrade to version 9.16 to receive the patch.

    00010578
    12.3K followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 CRITICAL - Unauthenticated SQL Editor endpoints enable pickle deserialization path (CVE-2026-12046) In pgAdmin 4 server mode, two state-mutating SQL Editor endpoints were exposed without the @pga_login_required authentication decorator, allowing unauthenticated requests to reach code paths that perform pickle deserialization from session data. While full remote code execution requires forging a server-side session file containing a malicious pickle payload, that becomes feasible if an attacker can obtain the Flask SECRET_KEY and has write access to the sessions directory. This combination turns an auth bypass into a high-impact deserialization chain, potentially resulting in arbitrary code execution under the pgAdmin service account. Real-world impact includes complete compromise of the pgAdmin host, database credential theft, and lateral movement via stored connections. 👉 Affected: pgAdmin 4 server mode 6.9 to <9.16 | Upgrade to 9.16

    Post summary

    The post discloses an authentication bypass in pgAdmin 4 that enables unauthenticated pickle deserialization, potentially leading to RCE if an attacker obtains the Flask SECRET_KEY. The CVE is mitigated by upgrading to version 9.16.

    0001073
    219 followersView on X

Explore more