CVE-2026-7813 Details
Description
Authorization vulnerability in pgAdmin 4 server mode affecting Server Groups, Servers, Shared Servers, Background Processes, and Debugger modules. Multiple endpoints fetched user-owned objects without filtering by the requesting user's identity. An authenticated user could access another user's private servers, server groups, background processes, and debugger function arguments by guessing object IDs. Additionally, the Shared Servers feature contained multiple issues including credential leakage (passexec_cmd, passfile, SSL keys), privilege escalation via writable passexec_cmd (a shell command executed when establishing the connection) allowing arbitrary command execution in the owner's process context, and owner-data corruption via SQLAlchemy session mutations. Several owner-only fields (passexec_cmd, passexec_expiration, db_res, db_res_type) were writable by non-owners through the API, and additional fields (kerberos_conn, tags, post_connection_sql) lacked per-user persistence so non-owner edits mutated the owner's record. Fix centralises access control via a new server_access module, scopes all user-owned models with a UserScopedMixin, returns HTTP 410 from connection_manager when access is denied in server mode, suppresses owner-only fields for non-owners across the merge / API response / ServerManager paths, and adds an explicit owner-only write guard. The remediation landed in two pull requests; both are referenced. This issue affects pgAdmin 4: before 9.15.
An authorization vulnerability exists in pgAdmin 4 in server mode, prior to 9.15, affecting various modules including Server Groups, Servers, Shared Servers, Background Processes, and Debugger. The vulnerability arises because multiple endpoints retrieve user-owned objects without proper filtering by the requesting user's identity. This flaw enables an authenticated user to access another user's private servers, server groups, background processes, and debugger function arguments by merely guessing object IDs. Furthermore, the Shared Servers feature has several issues, such as credential leakage (including passexec_cmd, passfile, and SSL keys), privilege escalation through writable passexec_cmd (which allows arbitrary command execution in the owner's process context), and owner-data corruption via SQLAlchemy session mutations. Several fields meant for owners only were accessible for writing by non-owners through the API, and other fields lacked per-user persistence, causing non-owner edits to alter the owner's record.
The vulnerability has been addressed in two pull requests, which can be found in the pgAdmin 4 GitHub repository.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 11, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/pgadmin-org/pgadmin4/pull/9830 | PostgreSQL | Issue TrackingPatch |
| https://github.com/pgadmin-org/pgadmin4/pull/9835 | PostgreSQL | Issue TrackingPatch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-284 | Improper Access Control | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| pgadmin pgadmin 4 | < 9.15 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | PostgreSQL |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 26, 2026 | Initial Analysis | [email protected] |
| May 11, 2026 | CVE Modified | CISA-ADP |
| May 11, 2026 | New CVE Received | PostgreSQL |