FOFA[verified]@fofabotGeneral
The post alerts to three pgAdmin 4 vulnerabilities with high CVSS scores, noting unauthenticated RCE and stored XSS, but offers no proof of exploitation, patching, or active use evidence.
yousukezan[verified]@yousukezanPatch
pgAdmin 4 fixed three high‑score vulnerabilities (XSS, authentication bypass, AI assistant SQL injection) in version 9.16; the text provides technical details but no PoC, exploit code, or evidence of active exploitation.
Netlas.io[verified]@Netlas_ioDisclosure
The tweet announces a new RCE vulnerability (CVE‑2026‑12046) in pgAdmin, gives technical details, and links to a resource that likely contains a PoC.
GovCERT.CZ[verified]@GOVCERT_CZPatch
The recent pgAdmin 4 release contains three critical CVEs (CVE‑2026‑12045/12046/12048) that enable unauthenticated remote code execution, AI assistant prompt injection, and stored XSS; immediately upgrade to version 9.16 or newer to mitigate these threats.
Upwind Security MDR[verified]@UpwindMDRDisclosure
The post discloses an authentication bypass in pgAdmin 4 that enables unauthenticated pickle deserialization, potentially leading to RCE if an attacker obtains the Flask SECRET_KEY. The CVE is mitigated by upgrading to version 9.16.
CCB Alert@CCBalertPatch
The advisory warns of critical RCE and XSS vulnerabilities in pgAdmin 4, provides CVSS scores and CVE IDs, and directs readers to apply the linked patch.
Daily CyberSecurity@the_yellow_fallPatch
Three critical XSS and RCE vulnerabilities were disclosed in pgAdmin 4; users are advised to upgrade to version 9.16 to receive the patch.