TGViewer
Netlas.io Netlas.io @netlas · 2.32K subscribers
Post #584 789
CVE-2026-12046: RCE vulnerability in pgAdmin 4, 9.5 rating 🔥

Two SQL Editor endpoints were missing the login-required decorator and were reachable without authentication in server mode. This exposes an unauthenticated remote code execution path in the pgAdmin process.

Search at Netlas.io:
👉 Link: https://nt.ls/jbYEF
👉 Dork: http.title:"pgAdmin" OR http.headers.set_cookie:"pga4_session=" OR http.favicon.hash_sha256:c3251099ffc5ed057dcbb624adbe79fa5794a0c64684442c1eaf1abc3edf7bde OR http.favicon.hash_sha256:6afa287fc6721817d9931bd8d7a796646ea535596f8bb038ff048666e19cfd17

Read more:
https://github.com/pgadmin-org/pgadmin4/issues/10072
  • ❤ 3
  • 🔥 3
  • 👍 2
  • 👾 2
More from @netlas
  1. Sep 23, 2026CVE-2026-87902: Path Traversal in WordPress leading to RCE, 9.2 Rating 🔥 Another newly di…
  2. Sep 22, 2026CVE-2026-93952: Improper Input Validation in VeloCloud Orchestrator, 10.0 Rating 🔥 A rece…
  3. Sep 21, 2026CVE-2026-13684 and others: Multiple vulnerabilities in Synology DSM, up to 9.8 Rating 🔥 S…
  4. Sep 18, 202611 new vulnerabilities in WordPress, no CVE assigned yet ❗️ WordPress 7.1.1 security relea…
  5. Sep 17, 2026CVE-2026-20329 and others: Multiple vulnerabilities in Cisco ASA, up to 9.9 Rating 🔥 Cisc…
  6. Sep 16, 2026CVE-2026-61642: Request smuggling is possible in Squid proxy, 7.7 Rating 🔥 A recently dis…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →