Critical Vulnerabilities in pgAdmin 4 Expose Databases to Remote Code Execution

Critical Vulnerabilities in pgAdmin 4 Expose Databases to Remote Code Execution

23h ago GbhackersCybersecuritynewsCcb.Belgium.Benvd.nist.gov 92% similarity 74.0
Share:

Article Content

Browse articles
ThreatCluster

pgAdmin 4 version 9.16 was released to patch seven vulnerabilities, including critical issues tracked as CVE-2026-12044 to CVE-2026-12050. These vulnerabilities could allow attackers to execute arbitrary commands, gain unauthorized access, or inject malicious scripts. Notably, CVE-2026-12045 allows remote code execution through a read-only transaction bypass, while CVE-2026-12046 exposes unauthenticated endpoints. CVE-2026-12048 presents a stored cross-site scripting risk that can lead to credential theft. The vulnerabilities affect a wide range of PostgreSQL database deployments, necessitating immediate updates. The Centre for Cybersecurity Belgium has issued advisories urging organizations to prioritize patching. The release also includes 64 bug fixes and usability enhancements.

Key Points: • pgAdmin 4 version 9.16 fixes seven critical vulnerabilities, including remote code execution risks. • CVE-2026-12045 allows attackers to bypass read-only transactions and execute commands. • Immediate patching is recommended due to the potential for unauthorized access and credential theft.

ThreatCluster AI

Timeline

2026-06-18
CVE-2026-12044 to CVE-2026-12050 published
Seven vulnerabilities in pgAdmin 4 were disclosed, including critical SQL injection and XSS issues.
Gbhackers
2026-06-18
CVE-2026-12048 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-18
CVE-2026-12049 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-18
CVE-2026-12047 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-18
CVE-2026-12046 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-18
CVE-2026-12045 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-22
pgAdmin 4 version 9.16 released
The pgAdmin Development Team released an update addressing seven vulnerabilities and introducing new features.
Gbhackers
2026-06-23
Advisory issued by Centre for Cybersecurity Belgium
The CCB recommended immediate patching of pgAdmin 4 due to critical vulnerabilities that could be exploited.
Ccb.Belgium.Be

Community

Browse all →