Junglewise Threat Intelligence

CVE-2026-1707: PYSEC-2026-2864 - pgadmin4 affected by a Restore restriction bypass via key disclosure vulnerability

CVE-2026-1707 · Severity: low · CVSS 3.1 · Published 2026-07-13

Technologies: pgadmin4 (PyPI). Vendors: PyPI, pgAdmin.

Executive brief

pgAdmin 4 is a web-based management tool for PostgreSQL databases. When running in server mode and performing SQL file restores, the application fails to properly mask encryption keys used to restrict dangerous commands. An attacker with web interface access can observe restore operations, extract the restriction key in real time, and inject malicious commands to execute code on the pgAdmin host.

Technical details

The vulnerability is a cryptographic key disclosure flaw affecting pgAdmin 4's restore functionality in server mode with PLAIN-format dump files. The \restrict key—used to disable dangerous meta-commands during restore operations—is exposed and observable by authenticated users through the web interface. An attacker can perform a race condition attack to overwrite the restore script mid-operation with a payload containing \unrestrict <key> to re-enable meta-commands, achieving reliable remote code execution on the pgAdmin host. The vulnerability affects all versions through 9.11 and is fixed in version 9.12. Exploitation requires authentication and access to the pgAdmin web interface, but no user interaction beyond observing an active restore.

Affected products

  • pgAdmin pgAdmin 4 4.20 through 9.11; fixed in 9.12

Timeline

  • 2026-02-05: disclosed
  • 2026-02-05: patched: Fixed in version 9.12

References

Related threats