Bug 2536448 - CVE-2026-86863 pgadmin4: authentication bypass via a client-controlled identity header in Webserver authentication mode [fedora-all]
Summary: CVE-2026-86863 pgadmin4: authentication bypass via a client-controlled identi...
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: pgadmin4
Version: rawhide
Hardware: Unspecified
OS: Unspecified
urgent
urgent
Target Milestone: ---
Assignee: Sandro Mani
QA Contact:
URL:
Whiteboard: {"flaws": ["da5cc606-d3cb-4689-9aa8-8...
Depends On:
Blocks: CVE-2026-86863
TreeView+ depends on / blocked
 
Reported: 2026-09-17 17:56 UTC by Guilherme de Almeida Suckevicz
Modified: 2026-09-27 01:12 UTC (History)
1 user (show)

Fixed In Version: pgadmin4-9.18-1.fc45 pgadmin4-9.18-1.fc44 pgadmin4-9.18-1.fc43
Clone Of:
Environment:
Last Closed: 2026-09-27 00:29:03 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Guilherme de Almeida Suckevicz 2026-09-17 17:56:35 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

pgAdmin 4's Webserver authentication source is intended to accept an identity asserted by the web server or reverse proxy in front of pgAdmin, delivered through the WSGI/CGI environment. WebserverAuthentication.get_user() read config.WEBSERVER_REMOTE_USER from request.environ and, when that returned nothing, fell back to reading the same name directly from the inbound HTTP request headers via request.headers.get(). An inbound HTTP header is written by whoever sends the request, so any client able to reach pgAdmin could supply that header itself and be authenticated as any username it named, including an existing Administrator, without presenting a password or any other credential. The environment lookup could also be satisfied by a client-supplied header whenever WEBSERVER_REMOTE_USER was configured to an HTTP_-prefixed or hyphenated name such as HTTP_X_FORWARDED_USER or X-Forwarded-User, since WSGI servers place inbound headers into the environment under exactly those names. Deployments are affected only when 'webserver' is enabled in AUTHENTICATION_SOURCES.

The fix distinguishes a genuine CGI/WSGI variable from a header-derived one and implicitly trusts only the former. A header-asserted identity is now accepted only when the operator explicitly opts in via WEBSERVER_REMOTE_USER_FROM_HEADER, the request arrives from a peer listed in WEBSERVER_TRUSTED_PROXIES, and, when configured, a shared secret supplied in WEBSERVER_SHARED_SECRET_HEADER matches WEBSERVER_SHARED_SECRET under a constant-time comparison. The trusted-peer check deliberately reads the real socket peer address rather than request.remote_addr, because ProxyFix rewrites the latter from the client-controlled X-Forwarded-For header and would otherwise allow an attacker to claim to be the trusted proxy. As defence in depth, login() now refuses any account whose auth_source is not 'webserver', so a misconfigured trust gate cannot be used to assume an internal or LDAP account.

This issue affects pgAdmin 4: from 6.2 before 9.18.

Comment 1 Fedora Update System 2026-09-18 19:45:09 UTC
FEDORA-2026-c070c47328 (pgadmin4-9.18-1.fc44) has been submitted as an update to Fedora 44.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-c070c47328

Comment 2 Fedora Update System 2026-09-18 19:45:21 UTC
FEDORA-2026-dddd2792e3 (pgadmin4-9.18-1.fc43) has been submitted as an update to Fedora 43.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-dddd2792e3

Comment 3 Fedora Update System 2026-09-18 19:45:31 UTC
FEDORA-2026-035cf95dc5 (pgadmin4-9.18-1.fc45) has been submitted as an update to Fedora 45.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-035cf95dc5

Comment 4 Fedora Update System 2026-09-19 01:40:24 UTC
FEDORA-2026-035cf95dc5 has been pushed to the Fedora 45 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-035cf95dc5`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2026-035cf95dc5

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 5 Fedora Update System 2026-09-19 02:19:16 UTC
FEDORA-2026-c070c47328 has been pushed to the Fedora 44 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-c070c47328`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2026-c070c47328

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 6 Fedora Update System 2026-09-19 02:23:03 UTC
FEDORA-2026-dddd2792e3 has been pushed to the Fedora 43 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-dddd2792e3`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2026-dddd2792e3

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 7 Fedora Update System 2026-09-27 00:29:03 UTC
FEDORA-2026-035cf95dc5 (pgadmin4-9.18-1.fc45) has been pushed to the Fedora 45 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 8 Fedora Update System 2026-09-27 00:57:20 UTC
FEDORA-2026-c070c47328 (pgadmin4-9.18-1.fc44) has been pushed to the Fedora 44 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 9 Fedora Update System 2026-09-27 01:12:12 UTC
FEDORA-2026-dddd2792e3 (pgadmin4-9.18-1.fc43) has been pushed to the Fedora 43 stable repository.
If problem still persists, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.