LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2026-17349

pgadmin · pgadmin 4

Published
CVSS9.6
Severitycritical
WeaknessCWE-522
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

Description

/misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, when passed the id of an existing server, clones that server via Server.clone(), which copies every column from the source row, including user_id, shared, shared_username, and the stored credential fields password, save_password, and tunnel_password. When a non-owner triggered an adhoc connect against another user's (in practice, typically an administrator's) shared server, the clone inherited that user's ownership, shared flag, and stored database credentials verbatim. pgAdmin persisted this cross-tenant, credential-bearing server row before the connection was even attempted, so it survived eve

References

← Back to the CVE Tracker

Our coverage of CVE-2026-17349

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-17349.