CVE-2026-12050: fallo de gravedad media en pgadmin.org pgAdmin 4
pgAdmin 4: SQL injection in named restore point endpoint
Publicada el · Actualizada el
13Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 5.3epss 0.4%
probabilidad de explotación
0.4%top 65% de las CVE
explotación observada
noninguna fuente lo reporta
SQL injection in pgAdmin 4's named restore point endpoint (POST /browser/server/restore_point/{gid}/{sid}). The user-supplied 'value' field was interpolated directly into the SQL string with str.format() instead of being passed as a bound parameter, allowing an authenticated pgAdmin user with a connected PostgreSQL session to inject additional statements through that endpoint.
The injected SQL executes under the database role the user is already authenticated as. The defect does not cross a privilege boundary -- the user already has direct SQL access to that role through the Query Tool -- so the attacker gains no capability beyond what their database role already grants them. The marginal impact accounts for the fact that the injection path is not the documented SQL-execution interface, so a deployment that gates the Query Tool at the application layer could see SQL executed through a path it did not anticipate.
Fix passes the restore point name as a bound parameter and schema-qualifies the function call as pg_catalog.pg_create_restore_point so a non-default search_path on the connection cannot redirect the call to a shadow definition. A regression test asserts the value arrives as a bound parameter and not spliced into the SQL string.
This issue affects pgAdmin 4: from 1.0 before 9.16.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Productos afectados
pgadmin.org · pgAdmin 4CVEs relacionadas — pgadmin.org pgAdmin 4
En el mismo producto, de las más peligrosas a las menos.
CVE-2024-2044CRITICALUnsafe Deserialisation and Remote Code Execution by an Authenticated user in pgAdmin 4EPSS 79.5%CVE-2024-3116HIGHRemote Code Execution Vulnerability through the validate binary path API in pgAdmin 4EPSS 65.6%CVE-2025-2945CRITICALpgAdmin 4: Remote Code Execution in Query Tool and Cloud DeploymentEPSS 56.3%CVE-2025-12762CRITICALRemote Code Execution vulnerability when restoring PLAIN-format SQL dumps in server mode (pgAdmin 4)EPSS 12.7%CVE-2024-9014CRITICALOAuth2 client id and secret exposed through the web browser in pgAdmin 4EPSS 9.7%CVE-2026-7816HIGHpgAdmin 4: OS command injection in Import/Export query export via psql metacommand breakoutEPSS 2.2%