Threat Advisory

pgAdmin 4 Flaw Facilitates Validation Disabling and User Deception

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-86863 with a CVSS score of 9.8 is a critical authentication bypass flaw in pgAdmin 4 that allows remote actors to forge the X-Forwarded-User identity header enabling them to log in as administrators without passwords when Webserver mode is active. This vulnerability resides in the application's Webserver authentication module which improperly fell back to reading raw HTTP headers when environment variables were absent in WSGI or CGI deployments. Organizations must deploy the latest fixed release immediately to secure their database environments and administrators unable to patch immediately should disable Webserver authentication and use internal accounts. With developers and administrators using pgAdmin to manage PostgreSQL deployments this vulnerability poses a severe danger to mission-critical database clusters allowing intruders to execute arbitrary SQL queries extract confidential records tamper with tables or destroy entire database schemas. The remote attack vector makes this a priority vulnerability affecting pgAdmin 4.

RECOMMENDATION:

We recommend you to update pgAdmin 4 to version 9.18 or later.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-86863 with a CVSS score of 9.8 is a critical authentication bypass flaw in pgAdmin 4 that allows remote actors to forge the X-Forwarded-User identity header enabling them to log in as administrators without passwords when Webserver mode is active. This vulnerability resides in the application's Webserver authentication module which improperly fell back to reading raw HTTP headers when environment variables were absent in WSGI or CGI deployments. Organizations must deploy the latest fixed release immediately to secure their database environments and administrators unable to patch immediately should disable Webserver authentication and use internal accounts. With developers and administrators using pgAdmin to manage PostgreSQL deployments this vulnerability poses a severe danger to mission-critical database clusters allowing intruders to execute arbitrary SQL queries extract confidential records tamper with tables or destroy entire database schemas. The remote attack vector makes this a priority vulnerability affecting pgAdmin 4.

RECOMMENDATION:

We recommend you to update pgAdmin 4 to version 9.18 or later.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu