CVE-2026-17347 Details
Description
The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an external command that returns a per-user encryption key, with %u in the configured string replaced by the current user's name. The previous implementation substituted the username directly into the command string and executed the result with subprocess.Popen(..., shell=True). Because the username can originate from an external authentication source (OAuth/OIDC claims, Kerberos, webserver auth) rather than a value pgAdmin fully controls, a username containing shell metacharacters (';', '$()', backticks, pipes, '&&', newlines) allowed an authenticated user to execute arbitrary commands as the pgAdmin service account in any deployment where the configured hook string uses %u. Fix tokenises the trusted, administrator-configured hook string into an argument vector first (using shlex in POSIX-quoting mode, with backslash-escaping disabled so Windows-style paths are not mis-parsed), substitutes the untrusted username into the individual argv elements, and executes with shell=False. The username is therefore always confined to a single argv element; any shell metacharacters it contains are inert. Administrators whose MASTER_PASSWORD_HOOK previously relied on shell features (pipes, redirection, environment-variable expansion, globbing) within the hook string itself must move that logic into the invoked script, since it is no longer interpreted by a shell. This issue affects pgAdmin 4: from 7.2 before 9.17.
A command injection vulnerability has been identified in pgAdmin 4 versions 7.2 prior to 9.17. The issue arises in the MASTER_PASSWORD_HOOK setting, which allows administrators to configure external commands that return per-user encryption keys. The vulnerability is created when usernames, sourced from external authentication methods, are substituted into the command string without proper sanitization. This oversight can be exploited by inserting shell metacharacters, leading to the execution of arbitrary commands as the pgAdmin service account.
This vulnerability has been fixed in pgAdmin 4 version 9.17. Administrators should update to this version. For those using Windows, it's important to note that the MASTER_PASSWORD_HOOK command must be quoted if it includes spaces, and should be invoked via an executable wrapper.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 31, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/pgadmin-org/pgadmin4/commit/e7a85767314e7b0fe0b35fe80b9c1af38f48dff6 | PostgreSQL | Patch |
| https://github.com/pgadmin-org/pgadmin4/commit/ea7e798aac27174d2bacee1d6e136bed76a95e23 | PostgreSQL | Patch |
| https://github.com/pgadmin-org/pgadmin4/issues/10191 | PostgreSQL | Issue TrackingPatchVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | PostgreSQL |
| CWE-88 | Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') | PostgreSQL |
Affected Products
| Product | Versions |
|---|---|
| pgadmin pgadmin 4 | >= 7.2, < 9.17 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 7, 2026 | Initial Analysis | [email protected] |
| Aug 1, 2026 | CVE Modified | CISA-ADP |
| Jul 31, 2026 | CVE Modified | CISA-ADP |
| Jul 31, 2026 | New CVE Received | PostgreSQL |