CVE-2026-7815Disclosure(pgadmin / pgadmin_4)

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

SQL injection vulnerability in pgAdmin 4 Maintenance Tool. Four user-supplied JSON fields (buffer_usage_limit, vacuum_parallel, vacuum_index_cleanup, reindex_tablespace) were concatenated directly into the rendered VACUUM/ANALYZE/REINDEX command and passed to psql --command. An authenticated user with the tools_maintenance permission could break out of the option syntax and execute arbitrary SQL on the connected PostgreSQL server. The injected SQL could in turn invoke COPY ... TO PROGRAM to escalate to operating-system command execution on the database host. Fix introduces server-side allow-listing of all four fields and switches reindex_tablespace from manual quoting to the qtIdent filter. This issue affects pgAdmin 4: before 9.15.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pgadmin_4

Threat summary

  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-05-11); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
pgadmin_4

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-05-11: 2Mentions · 2026-05-29: 1Mentions · 2026-05-31: 1Technical Details · 2026-05-11: 205-1105-2905-31
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-112
Disclosure2
2026-05-291
Disclosure1
2026-05-311
General1
Full discourse4 posts
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    General

    【脆弱性情報】 CVE-2026-7815 pgAdmin 4の脆弱性について https://www.cybernote.click/2026/05/24/%e3%80%90%e8%84%86%e5%bc%b1%e6%80%a7%e6%83%85%e5%a0%b1%e3%80%91-cve-2026-7815-pgadmin-4%e3%81%ae%e8%84%86%e5%bc%b1%e6%80%a7%e3%81%ab%e3%81%a4%e3%81%84%e3%81%a6/ #IT #Security #cybersecurity

    Post summary

    The post references CVE-2026-7815 for pgAdmin 4 but provides no substantive information about the vulnerability or its exploitation.

    0001047
    209 followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    Disclosure

    【脆弱性情報】 CVE-2026-7815 pgAdmin 4の脆弱性について https://www.cybernote.click/2026/05/24/%e3%80%90%e8%84%86%e5%bc%b1%e6%80%a7%e6%83%85%e5%a0%b1%e3%80%91-cve-2026-7815-pgadmin-4%e3%81%ae%e8%84%86%e5%bc%b1%e6%80%a7%e3%81%ab%e3%81%a4%e3%81%84%e3%81%a6/ #IT #Security #cybersecurity

    Post summary

    The post announces the existence of a pgAdmin 4 vulnerability (CVE‑2026‑7815) but provides no technical details, PoC, or evidence of exploitation.

    0001044
    208 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-7815 SQL injection vulnerability in pgAdmin 4 Maintenance Tool. Four user-supplied JSON fields (buffer_usage_limit, vacuum_parallel, vacuum_index_cleanup, reindex_tablespac… https://www.cve.org/CVERecord?id=CVE-2026-7815

    Post summary

    A new CVE (CVE-2026-7815) has been disclosed, identifying an SQL injection flaw in pgAdmin 4's Maintenance Tool involving user-supplied JSON fields.

    0000060
    57.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-7815 SQL Injection in pgAdmin 4 Maintenance Tool Enables Arbitr... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7815 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The tweet announces the discovery of CVE-2026-7815, a SQL injection vulnerability in pgAdmin 4's maintenance tool, without providing exploitation details or mitigation information.

    0000044
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppgadminpgadmin_4-postgresql-

Explore more