SQL Injection Vulnerability in pgAdmin 4 Affecting Multiple Dialog Templates
CVE-2026-12044
What is CVE-2026-12044?
The SQL injection vulnerability in pgAdmin 4 allows authenticated users to exploit dialog templates that render user-supplied descriptions directly within SQL queries. This flaw occurs in various dialog templates, leading to potential execution of arbitrary SQL commands. Attackers can craft malicious descriptions that include characters like apostrophes to break out of string literals, which may trigger unwanted operations under the permissions granted to the authenticated user. While this vulnerability does not allow privilege escalation, it exposes a severe risk, notably for users with elevated privileges such as PostgreSQL superusers. The issue was discovered during an audit and has multiple affected sites across the application. Mitigation includes updates to templating practices and enhanced error handling to prevent similar issues in the future.
Affected Version(s)
pgAdmin 4 1.0 < 9.16
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
