Junglewise Threat Intelligence

CVE-2026-7816: PostgreSQL pgAdmin 4 OS command injection in Import/Export query export

CVE-2026-7816 · Severity: high · CVSS 8.8 · Published 2026-05-11

Technologies: pgadmin4 (PyPI), PostgreSQL pgAdmin 4. Vendors: PyPI, PostgreSQL.

Executive brief

pgAdmin 4 is a popular management tool for PostgreSQL databases. A security vulnerability in its Import/Export feature allows an authorized user to execute unauthorized commands or write files on the server hosting the application. This could lead to a full system compromise, data theft, or disruption of operations.

Technical details

An OS command injection (CWE-78) exists in pgAdmin 4 due to improper sanitization of user-supplied input before it is interpolated into a psql \copy metacommand template. An authenticated attacker can provide a crafted query containing ") TO PROGRAM 'cmd'" to break out of the command context and execute arbitrary shell commands or write to local files. Other fields including format, on_error, and log_verbosity were also found to be vulnerable to raw interpolation. The vulnerability is fixed in version 9.15 by implementing a parenthesis-balancing parser, allow-listing specific fields, and rejecting null bytes.

Affected products

  • PostgreSQL pgAdmin 4 9.4 to < 9.15

Timeline

  • 2026-05-01: disclosed: Issue reported on GitHub
  • 2026-05-11: advisory: CVE published and NVD entry created
  • 2026-05-11: patched: Fixed in version 9.15

References

Related threats