OS Command Injection Vulnerability in pgAdmin 4 by pgAdmin.org
CVE-2026-7816

8.7HIGH

Key Information:

Status
Vendor
CVE Published:
11 May 2026

What is CVE-2026-7816?

A vulnerability exists in pgAdmin 4 versions prior to 9.15, where user input in the Import/Export query export feature is not properly sanitized, allowing for OS command injection. An authenticated user can exploit this flaw by injecting specific commands that break out of the intended query context, potentially executing arbitrary commands on the server or writing files to arbitrary locations. To mitigate this risk, recent fixes have implemented a new parser alongside allow-lists and enhanced validation checks to prevent malicious input.

Affected Version(s)

pgAdmin 4 9.4

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Chung Kim (chungkn), OneMount Group
.