logo

Critical 9.4 CVSS pgAdmin 4 Flaws Enable Full OS Command Execution

ID: 0207f0bc-a7a3-53f7-a2d8-3c70093d7c65

STIX ID: report--0207f0bc-a7a3-53f7-a2d8-3c70093d7c65

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-05-15

Date Updated: 2026-05-15

Author: Ddos

...
...

pgAdmin released version 9.15 to fix multiple high-severity vulnerabilities affecting all versions prior to 9.15, including authorization bypasses, privilege escalation via writable passexec_cmd, SQL injection that can escalate to OS command execution (COPY … TO PROGRAM), unsafe session deserialization leading to RCE, SSRF via LLM API config, and path traversal in the File Manager; administrators are urged to upgrade immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.