CVE-2026-86863

LOW

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

0.0/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-09-18: 309-18
Referenced assets3 URLs
Full discourse3 posts
  • Daily CyberSecurity@Daily_CyberSec

    A critical pgAdmin 4 authentication bypass (CVE-2026-86863) allows remote admin takeover. Patch this pgAdmin 4 authentication bypass vulnerability now. #pgAdmin #PostgreSQL #CVE202686863 #AuthenticationBypass #Cybersecurity https://securityonline.info/pgadmin-4-authentication-bypass-cve-2026-86863/

    02051379
    12.9K followersView on X
  • NEXSIGHT@NEXSIGHTNEWS

    PostgreSQL管理ツール「pgAdmin 4」のv9.18が4件の脆弱性を修正 — Webserver認証モードでは、pgAdminに到達できる任意のクライアントが管理者を含む任意の利用者になりすませた https://cyber.nexsight.co/articles/2026/09/18/pgadmin4-v9-18-authentication-bypass-cve-2026-86863-2026-09-18/

    0000015
    67 followersView on X
  • VulnTracker@vuln_tracker

    A single HTTP header can log you into pgAdmin 4 as Administrator no password required (CVSS 9.8). CVE-2026-86863 affects pgAdmin's Webserver authentication mode, which trusts a client-controlled identity header instead of verifying it came from a real proxy. Anyone who can reach the app can authenticate as any username they choose. Affects pgAdmin 4 from 6.2 before 9.18. The fix adds an explicit opt-in, a trusted-proxy check, and a shared secret. Details: http://vulntracker.io/cves/CVE-2026-86863 #pgAdmin #CVE #PostgreSQL #InfoSec #CyberSecurity

    0000037
    752 followersView on X

Explore more