OS Command Injection Vulnerability in pgAdmin 4 by pgAdmin.org
CVE-2026-7816
8.7HIGH
What is CVE-2026-7816?
A vulnerability exists in pgAdmin 4 versions prior to 9.15, where user input in the Import/Export query export feature is not properly sanitized, allowing for OS command injection. An authenticated user can exploit this flaw by injecting specific commands that break out of the intended query context, potentially executing arbitrary commands on the server or writing files to arbitrary locations. To mitigate this risk, recent fixes have implemented a new parser alongside allow-lists and enhanced validation checks to prevent malicious input.
Affected Version(s)
pgAdmin 4 9.4
