Technology · PostgreSQL
PostgreSQL pgAdmin 4 vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 26 vulnerabilities in PostgreSQL pgAdmin 4: 0 in the last 7 days and 11 in the last 90 days, 8 of them critical and 0 exploited in the wild. The most recent, CVE-2026-86864, was published on 17 September 2026.
- Last 7 days
- 0
- Last 90 days
- 11
- Critical, all time
- 8
- Exploited in the wild
- 0
About PostgreSQL pgAdmin 4
pgAdmin 4 is an open source management and administration tool for the PostgreSQL database.
Latest PostgreSQL pgAdmin 4 vulnerabilities
- CVE-2026-86864: pgAdmin 4 Backup tool arbitrary file write and connection string injectionhighCVSS 8.8EPSS 0.6%
- CVE-2026-86863: pgAdmin 4 authentication bypass in webserver modecriticalCVSS 9.8EPSS 0.6%
- CVE-2026-86862: pgAdmin 4 connection string injection in Restore and Maintenance toolsmediumCVSS 6.5EPSS 0.4%
- CVE-2026-86861: pgAdmin 4 File Manager TOCTOU symlink write bypass in save_filemediumCVSS 5.9EPSS 0.3%
- CVE-2026-17566: pgAdmin 4 OS command injection in Import/Export Data toolcriticalCVSS 9.9
- CVE-2026-17351: pgAdmin 4 SQL injection bypass in AI AssistantcriticalCVSS 9
- CVE-2026-17350: PostgreSQL pgAdmin 4 missing authorization in per-tool permissionsmediumCVSS 5.4
- CVE-2026-17349: PostgreSQL pgAdmin 4 credential leak in Workspaces adhoc connectioncriticalCVSS 9.6
- CVE-2026-17348: pgAdmin 4 missing authentication in multiple server-mode routesmediumCVSS 6.5
- CVE-2026-17347: pgAdmin 4 OS command injection in MASTER_PASSWORD_HOOKhighCVSS 7.5
- CVE-2026-17346: pgAdmin 4 SQL injection in Statistics and Dependencies tabshighCVSS 8.8
- CVE-2026-12050: pgAdmin 4 SQL injection in named restore point endpointmediumCVSS 4.3
- CVE-2026-12049: pgAdmin 4 open redirect in multi-factor authentication flowmediumCVSS 4.3
- CVE-2026-12048: PostgreSQL pgAdmin 4 stored XSS in error and plan renderingcriticalCVSS 9.3
- CVE-2026-12047: PostgreSQL pgAdmin 4 HTML injection in cloud deployment modulelowCVSS 3.5
- CVE-2026-12046: pgAdmin 4 unauthenticated RCE in SQL Editor via pickle deserializationcriticalCVSS 9
- CVE-2026-12045: pgAdmin 4 SQL injection and RCE in AI AssistantcriticalCVSS 9
- CVE-2026-12044: pgAdmin 4 SQL injection in multiple dialog templates and stats viewshighCVSS 8.8
- CVE-2026-7820: PostgreSQL pgAdmin 4 account lockout bypass in login viewsmediumCVSS 6.5EPSS 0.3%
- CVE-2026-7819: PostgreSQL pgAdmin 4 symbolic-link path traversal in File ManagerhighCVSS 8.1EPSS 0.5%
- CVE-2026-7818: PostgreSQL pgAdmin 4 insecure deserialization in FileBackedSessionManagerhighCVSS 7EPSS 0.4%
- CVE-2026-7817: PostgreSQL pgAdmin 4 LFI and SSRF in LLM API endpointsmediumCVSS 6.5EPSS 0.4%
- CVE-2026-7816: PostgreSQL pgAdmin 4 OS command injection in Import/Export query exporthighCVSS 8.8EPSS 2.2%
- CVE-2026-7815: PostgreSQL pgAdmin 4 SQL injection in Maintenance ToolhighCVSS 8.8EPSS 0.6%
- CVE-2026-7814: PostgreSQL pgAdmin 4 stored XSS in Browser Tree and Explain VisualizermediumCVSS 4.8EPSS 0.3%
Most severe PostgreSQL pgAdmin 4 vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-7813: PostgreSQL pgAdmin 4 authorization bypass and RCE in server modecriticalCVSS 9.9EPSS 0.7%
- CVE-2026-17566: pgAdmin 4 OS command injection in Import/Export Data toolcriticalCVSS 9.9
- CVE-2026-86863: pgAdmin 4 authentication bypass in webserver modecriticalCVSS 9.8EPSS 0.6%
- CVE-2026-17349: PostgreSQL pgAdmin 4 credential leak in Workspaces adhoc connectioncriticalCVSS 9.6
- CVE-2026-12048: PostgreSQL pgAdmin 4 stored XSS in error and plan renderingcriticalCVSS 9.3
- CVE-2026-17351: pgAdmin 4 SQL injection bypass in AI AssistantcriticalCVSS 9
- CVE-2026-12046: pgAdmin 4 unauthenticated RCE in SQL Editor via pickle deserializationcriticalCVSS 9
- CVE-2026-12045: pgAdmin 4 SQL injection and RCE in AI AssistantcriticalCVSS 9
- CVE-2026-7816: PostgreSQL pgAdmin 4 OS command injection in Import/Export query exporthighCVSS 8.8EPSS 2.2%
- CVE-2026-7815: PostgreSQL pgAdmin 4 SQL injection in Maintenance ToolhighCVSS 8.8EPSS 0.6%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 7 | 3 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 4 | 1 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/pgadmin-4.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "PostgreSQL pgAdmin 4 vulnerabilities", https://junglewise.ai/threats/technologies/pgadmin-4, 26 September 2026.