Critical Vulnerabilities in pgAdmin 4 Expose Databases to Remote Code Execution
ID: d11988a5-e284-52f4-9666-664255b6ad10
STIX ID: report--d11988a5-e284-52f4-9666-664255b6ad10
Feed Name: ThreatCluster
pgAdmin 4 version 9.16 patches seven vulnerabilities (CVE-2026-12044 to CVE-2026-12050), including critical issues such as remote code execution via a read-only transaction bypass (CVE-2026-12045), unauthenticated endpoint exposure (CVE-2026-12046), and stored XSS leading to credential theft (CVE-2026-12048). The release affects a wide range of PostgreSQL deployments, includes 64 bug fixes and usability enhancements, and the Centre for Cybersecurity Belgium has advised organizations to prioritize immediate updates.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
