CVE-2026-17348
Received Received - Intake

Authentication Bypass in pgAdmin 4 Server Mode

Vulnerability report for CVE-2026-17348, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-31

Last updated on: 2026-07-31

Assigner: PostgreSQL

Description

In SERVER mode, pgAdmin 4 enforces authentication per route via the @pga_login_required decorator; the application's before_request hook only handles desktop-mode auto-login and the Kerberos/Webserver-auth redirect, so any route shipped without the decorator is reachable without authentication (CWE-306). This is the same defect class previously fixed as CVE-2026-12046 (the sqleditor close/update_connection routes). A follow-up sweep, prompted by a report describing an incomplete fix for CVE-2026-12046, found further routes missing @pga_login_required: the Constraints blueprint's nodes and proplist (object listing) routes and its delete route (a state-mutating DELETE that removes table constraints); preferences.get_all_cli (GET, discloses all CLI-settable preference values); debugger.close (DELETE); and schema_diff.close (DELETE). An unauthenticated network client could therefore enumerate constraint metadata, delete table constraints, read preference values, and force-close debugger or schema-diff sessions belonging to other users, without ever authenticating. Fix adds the missing @pga_login_required decorator (and the corresponding import to the Constraints module) to each of these routes. The change is decorator-only; no behavioral changes to the underlying handlers. This issue affects pgAdmin 4 in SERVER mode: the Constraints and Debugger routes from 1.0, the Schema Diff close route from 4.18, and preferences.get_all_cli from 8.2, all before 9.17.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-31
Last Modified
2026-07-31
Generated
2026-07-31
AI Q&A
2026-07-31
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
pgadmin pgadmin to 9.17 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in pgAdmin 4 (CVE-2026-17348) allows unauthenticated access to certain routes in SERVER mode due to missing authentication decorators. Routes like Constraints, Debugger, Schema Diff, and preferences.get_all_cli can be accessed without logging in, enabling actions like deleting table constraints, reading preference values, or closing sessions belonging to other users.

Detection Guidance

Check for unauthenticated access to specific pgAdmin 4 routes in SERVER mode. Inspect logs for requests to /constraints/nodes, /constraints/proplist, /constraints/delete, /preferences/get_all_cli, /debugger/close, or /schema_diff/close without prior authentication.

Impact Analysis

An attacker could exploit this to perform unauthorized actions such as deleting database constraints, accessing sensitive preference settings, or disrupting active debugger or schema-diff sessions of other users. This could lead to data loss, information disclosure, or service disruption in pgAdmin 4 instances running in SERVER mode.

Compliance Impact

This vulnerability could violate compliance requirements by allowing unauthorized access to sensitive data or system functions. For GDPR, it risks unauthorized data exposure or modification. For HIPAA, it may enable unauthorized access to protected health information. Organizations using pgAdmin 4 in SERVER mode must address this to maintain compliance.

Mitigation Strategies

Upgrade pgAdmin 4 to version 9.17 or later. Ensure the @pga_login_required decorator is applied to all affected routes. Review and restrict network access to pgAdmin 4 server interfaces.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-17348. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart