Forwarded National Information Security Analysis and Sharing Center Security Advisory Alert NISAC-200-202607-00000002
[Description]
Researchers have discovered multiple high-risk security vulnerabilities in pgAdmin 4 (CVE-2026-12044 to CVE-2026-12050). Among them, the most severe CVE-2026-12046 is an insecure deserialization (Insecure Deserialization) vulnerability. When the product operates in server mode, and the attacker knows the pgAdmin Flask SECRET_KEY and has permission to write to the pgAdmin Session directory, this vulnerability can be exploited to execute arbitrary code. Please confirm and apply patches as soon as possible.
[Affected Platform]
pgAdmin 4 versions 1.0 to 9.15
[Recommendations]
The official has released fixes for the vulnerabilities. Please refer to the official instructions for updates at the following URL: https://www.postgresql.org/about/news/pgadmin-4-v916-released-3324/
[References]
1. https://nvd.nist.gov/vuln/detail/CVE-2026-12044
2. https://nvd.nist.gov/vuln/detail/CVE-2026-12045
3. https://nvd.nist.gov/vuln/detail/CVE-2026-12046
4. https://nvd.nist.gov/vuln/detail/CVE-2026-12047
5. https://nvd.nist.gov/vuln/detail/CVE-2026-12048
6. https://nvd.nist.gov/vuln/detail/CVE-2026-12049
7. https://nvd.nist.gov/vuln/detail/CVE-2026-12050
8. https://www.postgresql.org/about/news/pgadmin-4-v916-released-3324/