Gbhackers Critical Vulnerabilities in pgAdmin 4 Expose Databases to Remote Code Execution
Article Content
- •pgAdmin 4 version 9.16 fixes seven critical vulnerabilities, including remote code execution risks.
- •CVE-2026-12045 allows attackers to bypass read-only transactions and execute commands.
- •Immediate patching is recommended due to the potential for unauthorized access and credential theft.
pgAdmin 4 version 9.16 was released to patch seven vulnerabilities, including critical issues tracked as CVE-2026-12044 to CVE-2026-12050. These vulnerabilities could allow attackers to execute arbitrary commands, gain unauthorized access, or inject malicious scripts. Notably, CVE-2026-12045 allows remote code execution through a read-only transaction bypass, while CVE-2026-12046 exposes unauthenticated endpoints. CVE-2026-12048 presents a stored cross-site scripting risk that can lead to credential theft. The vulnerabilities affect a wide range of PostgreSQL database deployments, necessitating immediate updates. The Centre for Cybersecurity Belgium has issued advisories urging organizations to prioritize patching. The release also includes 64 bug fixes and usability enhancements.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (9)
Following this threat?
Track Qnap and CVE-2026-12044 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…