CVE-2026-12046: RCE vulnerability in pgAdmin 4, 9.5 rating 🔥
Two SQL Editor endpoints were missing the login-required decorator and were reachable without authentication in server mode. This exposes an unauthenticated remote code execution path in the pgAdmin process.
Search at Netlas.io:
👉 Link: https://nt.ls/jbYEF
👉 Dork: http.title:"pgAdmin" OR http.headers.set_cookie:"pga4_session=" OR http.favicon.hash_sha256:c3251099ffc5ed057dcbb624adbe79fa5794a0c64684442c1eaf1abc3edf7bde OR http.favicon.hash_sha256:6afa287fc6721817d9931bd8d7a796646ea535596f8bb038ff048666e19cfd17
Read more:
https://github.com/pgadmin-org/pgadmin4/issues/10072
Post #584
789

- ❤ 3
- 🔥 3
- 👍 2
- 👾 2