Common Vulnerabilities and Exposures (CVE)

CVE-2026-17346

Jul 31, 2026 17:24:37 UTC

The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT ON / pgstattuple / pgstatindex templates to it, but missed several sinks that had been placed in test_sql_string_literal_lint.py's ALLOWLIST on the...

CVE-2026-17347

Jul 31, 2026 17:23:42 UTC

The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an external command that returns a per-user encryption key, with %u in the configured string replaced by the current user's name. The previous im...

CVE-2026-17348

Jul 31, 2026 17:23:08 UTC

In SERVER mode, pgAdmin 4 enforces authentication per route via the @pga_login_required decorator; the application's before_request hook only handles desktop-mode auto-login and the Kerberos/Webserver-auth redirect, so any route shipped wit...

CVE-2026-17349

Jul 31, 2026 17:21:53 UTC

/misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, when passed the id of an existing server, clones that server via Server.clone(), which copies every column from the source row, including user...

CVE-2026-48864

Jul 31, 2026 17:19:31 UTC

A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially crafted `.solv` fil...

CVE-2026-58047

Jul 31, 2026 17:17:56 UTC

HTTP Smuggling in cPanel allows potential leak of credentials.

CVE-2026-34490

Jul 31, 2026 17:17:33 UTC

Cleartext storage of sensitive information vulnerability in Johnson Controls XAAP Application on Android allows an attacker on a jailbroken or otherwise compromised device to Retrieve Sensitive Data. This issue affects XAAP Application: be...

CVE-2026-20316

Jul 31, 2026 17:15:14 UTC

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within th...

CVE-2026-58048

Jul 31, 2026 17:12:23 UTC

Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.

CVE-2026-17350

Jul 31, 2026 17:05:44 UTC

The per-tool permission system (custom roles / role-based tool permissions, introduced in pgAdmin 4 9.3) did not enforce its permission check consistently. In SERVER mode, pgAdmin 4 gates each tool behind a per-tool Flask-Security permissio...

CVE-2026-55100

Jul 31, 2026 17:03:41 UTC

hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API. Prior to 0.5.2, src/Vault.js concatenates unencoded identifier values including name, username, group, role, and version into Vault request paths and query str...

CVE-2026-17351

Jul 31, 2026 17:00:18 UTC

The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlparse, as exactly one non-transaction-control statement before running it inside a BEGIN TRANS...

CVE-2026-17566

Jul 31, 2026 16:59:40 UTC

pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-supplied SQL query into a Jinja template and passing the rendered line to psql via --command. To stop an attacker from breaking out of the (....

CVE-2026-54729

Jul 31, 2026 16:58:56 UTC

DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.0.5, is_url_safe can treat localhost as safe when DNS resolver 1.1.1.1 returns NXDOMAIN because dns.resolve4 yields no address a...

CVE-2026-59232

Jul 31, 2026 16:57:56 UTC

Cross-site Scripting in the lead index view in Roskus Prospero Flow CRM before 5.3.7 allows authenticated users holding the create or update lead permission to execute arbitrary JavaScript in the application origin via HTML markup stored in...