Bug 2536122 (CVE-2026-86862)
| Summary: | CVE-2026-86862 pgadmin4: connection-string injection via the database field in the Restore and Maintenance tools | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | Keywords: | Security |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in pgAdmin 4. Authenticated users with tools_restore or tools_maintenance permissions can exploit a connection-string injection issue in the Restore and Maintenance tools. By manipulating the 'database' field passed to the --dbname option of pg_restore and psql, an attacker can redirect the utility to an arbitrary server. This flaw allows for the disclosure of decrypted stored database passwords (via PGPASSWORD) and enables outbound connections from the pgAdmin host to arbitrary network locations.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2536446 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-09-17 15:53:48 UTC
|