CVE-2026-7813Disclosure(pgadmin / pgadmin_4)

LOWCVSS 9.4 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch pgadmin pgadmin_4 systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Authorization vulnerability in pgAdmin 4 server mode affecting Server Groups, Servers, Shared Servers, Background Processes, and Debugger modules. Multiple endpoints fetched user-owned objects without filtering by the requesting user's identity. An authenticated user could access another user's private servers, server groups, background processes, and debugger function arguments by guessing object IDs. Additionally, the Shared Servers feature contained multiple issues including credential leakage (passexec_cmd, passfile, SSL keys), privilege escalation via writable passexec_cmd (a shell command executed when establishing the connection) allowing arbitrary command execution in the owner's process context, and owner-data corruption via SQLAlchemy session mutations. Several owner-only fields (passexec_cmd, passexec_expiration, db_res, db_res_type) were writable by non-owners through the API, and additional fields (kerberos_conn, tags, post_connection_sql) lacked per-user persistence so non-owner edits mutated the owner's record. Fix centralises access control via a new server_access module, scopes all user-owned models with a UserScopedMixin, returns HTTP 410 from connection_manager when access is denied in server mode, suppresses owner-only fields for non-owners across the merge / API response / ServerManager paths, and adds an explicit owner-only write guard. The remediation landed in two pull requests; both are referenced. This issue affects pgAdmin 4: before 9.15.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pgadmin_4

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 3 mentions (2026-05-11); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
pgadmin_4

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-05-11: 3Mentions · 2026-05-27: 1Patch / Workaround · 2026-05-11: 1Technical Details · 2026-05-11: 2Technical Details · 2026-05-27: 105-1105-27
Signal classification2 categories
Disclosure
250.0%
General
250.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-113
Disclosure2General1
2026-05-271
General1
Full discourse4 posts
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 Critical - pgAdmin 4 Authorization Bypass Leading to Server Object Access & Privilege Escalation (CVE-2026-7813) Multiple pgAdmin 4 server-mode endpoints fail to enforce user scoping on Server Groups, Servers, Shared Servers, Background Processes, and Debugger modules. Authenticated users can access or modify other users’ objects by guessing IDs, leading to credential exposure (SSL keys, passfile), tampering with connection settings, and in some cases arbitrary command execution via writable passexec_cmd. 👉 Affected: pgAdmin 4 < 9.15 | Fix: 9.15

    Post summary

    The post discloses a critical authorization bypass in pgAdmin 4 that enables privilege escalation and arbitrary command execution, and references the patch version 9.15.

    00010103
    187 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-7813: pgAdmin 4 Authorization Bypass Vulnerability - What It Means for Your Business and How to Respond https://hubs.li/Q04h_XpW0

    Post summary

    The article headlines a pgAdmin 4 authorization bypass (CVE‑2026‑7813) and promises advice, but offers no PoC, exploit code, patch details or evidence of active attacks.

    0000043
    31 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-7813 Authorization vulnerability in pgAdmin 4 server mode affecting Server Groups, Servers, Shared Servers, Background Processes, and Debugger modules. Multiple endpoints f… https://www.cve.org/CVERecord?id=CVE-2026-7813

    Post summary

    The text announces CVE-2026-7813, an authorization flaw in pgAdmin 4 server mode affecting multiple modules, but provides no evidence of exploits, active use, or patches.

    0000071
    57.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-7813 Authorization Bypass in pgAdmin 4 Server Mode Affecting Multiple Modules https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7813

    Post summary

    The text references CVE-2026-7813 with a title and a link, but provides no further details or actionable information.

    0000045
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppgadminpgadmin_4-postgresql-

Explore more