SQL Injection Vulnerability in pgAdmin 4 Affecting Multiple Dialog Templates
CVE-2026-12044

8.7HIGH

Key Information:

Status
Vendor
CVE Published:
18 June 2026

What is CVE-2026-12044?

The SQL injection vulnerability in pgAdmin 4 allows authenticated users to exploit dialog templates that render user-supplied descriptions directly within SQL queries. This flaw occurs in various dialog templates, leading to potential execution of arbitrary SQL commands. Attackers can craft malicious descriptions that include characters like apostrophes to break out of string literals, which may trigger unwanted operations under the permissions granted to the authenticated user. While this vulnerability does not allow privilege escalation, it exposes a severe risk, notably for users with elevated privileges such as PostgreSQL superusers. The issue was discovered during an audit and has multiple affected sites across the application. Mitigation includes updates to templating practices and enhanced error handling to prevent similar issues in the future.

Affected Version(s)

pgAdmin 4 1.0 < 9.16

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jasser Chebbi <jasserchebbi@outlook.com>
Dave Page <dpage@pgadmin.org>
Ashesh Vashi <ashesh.vashi@enterprisedb.com>
.