【Security Vulnerability Alert】pgAdmin 4 has a high-risk security vulnerability (CVE-2026-86863), please confirm and take action as soon as possible

 
2026/10/8 ~ 2027/4/8
View Count:43

Forwarded National Information and Analysis Center for Cyber Security Cybersecurity Information Alert NISAC-200-202610-00000006

[Description]
Researchers have discovered an Authentication Bypass vulnerability (CVE-2026-86863) in pgAdmin 4. When the Webserver authentication source is enabled, an unauthenticated remote attacker can impersonate any user (including administrators) by sending specially crafted HTTP request headers, thereby obtaining pgAdmin administrative privileges. Please confirm and take action as soon as possible.

[Affected Platforms]
pgAdmin 4 versions 6.2 to 9.17

[Recommended Measures]
The vendor has released patches or updates for the vulnerability. Please refer to the official instructions for remediation. The URL is as follows: https://github.com/pgadmin-org/pgadmin4/issues/10383

[References]
1. https://nvd.nist.gov/vuln/detail/CVE-2026-86863
2. https://github.com/pgadmin-org/pgadmin4/issues/10383

Files
system_update_alt參考資料1
system_update_alt參考資料2
Top↑