logo

Critical Vulnerabilities in pgAdmin 4 Expose Databases to Remote Code Execution

ID: d11988a5-e284-52f4-9666-664255b6ad10

STIX ID: report--d11988a5-e284-52f4-9666-664255b6ad10

Feed Name: ThreatCluster

Threat Score
75/100

Date Published: 2026-06-22

Date Updated: 2026-06-23

...
...

pgAdmin 4 version 9.16 patches seven vulnerabilities (CVE-2026-12044 to CVE-2026-12050), including critical issues such as remote code execution via a read-only transaction bypass (CVE-2026-12045), unauthenticated endpoint exposure (CVE-2026-12046), and stored XSS leading to credential theft (CVE-2026-12048). The release affects a wide range of PostgreSQL deployments, includes 64 bug fixes and usability enhancements, and the Centre for Cybersecurity Belgium has advised organizations to prioritize immediate updates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.