Bug 2509859 - CVE-2026-17348 pgadmin4: pgAdmin 4: Unauthenticated access allows data manipulation and information disclosure [fedora-all]
Summary: CVE-2026-17348 pgadmin4: pgAdmin 4: Unauthenticated access allows data manipu...
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: pgadmin4
Version: rawhide
Hardware: Unspecified
OS: Unspecified
medium
medium
Target Milestone: ---
Assignee: Sandro Mani
QA Contact:
URL:
Whiteboard: {"flaws": ["9ab917b8-0713-4aba-a144-d...
Depends On:
Blocks: CVE-2026-17348
TreeView+ depends on / blocked
 
Reported: 2026-07-31 18:47 UTC by Todd Cullum
Modified: 2026-08-09 01:17 UTC (History)
1 user (show)

Fixed In Version: pgadmin4-9.17-1.fc44 pgadmin4-9.17-1.fc43
Clone Of:
Environment:
Last Closed: 2026-08-09 00:59:04 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Todd Cullum 2026-07-31 18:47:34 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

In SERVER mode, pgAdmin 4 enforces authentication per route via the @pga_login_required decorator; the application's before_request hook only handles desktop-mode auto-login and the Kerberos/Webserver-auth redirect, so any route shipped without the decorator is reachable without authentication (CWE-306). This is the same defect class previously fixed as CVE-2026-12046 (the sqleditor close/update_connection routes).

A follow-up sweep, prompted by a report describing an incomplete fix for CVE-2026-12046, found further routes missing @pga_login_required: the Constraints blueprint's nodes and proplist (object listing) routes and its delete route (a state-mutating DELETE that removes table constraints); preferences.get_all_cli (GET, discloses all CLI-settable preference values); debugger.close (DELETE); and schema_diff.close (DELETE). An unauthenticated network client could therefore enumerate constraint metadata, delete table constraints, read preference values, and force-close debugger or schema-diff sessions belonging to other users, without ever authenticating.

Fix adds the missing @pga_login_required decorator (and the corresponding import to the Constraints module) to each of these routes. The change is decorator-only; no behavioral changes to the underlying handlers.

This issue affects pgAdmin 4 in SERVER mode: the Constraints and Debugger routes from 1.0, the Schema Diff close route from 4.18, and preferences.get_all_cli from 8.2, all before 9.17.

Comment 1 Fedora Update System 2026-08-02 09:49:18 UTC
FEDORA-2026-f0550055a7 (pgadmin4-9.17-1.fc44) has been submitted as an update to Fedora 44.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-f0550055a7

Comment 2 Fedora Update System 2026-08-02 09:49:21 UTC
FEDORA-2026-bacb14f76f (pgadmin4-9.17-1.fc43) has been submitted as an update to Fedora 43.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-bacb14f76f

Comment 3 Fedora Update System 2026-08-09 00:59:04 UTC
FEDORA-2026-f0550055a7 (pgadmin4-9.17-1.fc44) has been pushed to the Fedora 44 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 4 Fedora Update System 2026-08-09 01:17:39 UTC
FEDORA-2026-bacb14f76f (pgadmin4-9.17-1.fc43) has been pushed to the Fedora 43 stable repository.
If problem still persists, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.