【資安漏洞預警】pgAdmin 4存在多項高風險安全漏洞(CVE-2026-12044至CVE-2026-12050),請儘速確認並進行修補
【Security Vulnerability Alert】pgAdmin 4 has multiple high-risk security vulnerabilities (CVE-2026-12044 to CVE-2026-12050), please confirm and apply patches as soon as possible

發布單位:圖資處數位服務組
日期範圍:2026/7/21 ~ 2027/1/21
 
發布單位:圖資處數位服務組
日期範圍:2026/7/21 ~ 2027/1/21
行政 行政公告
全體

轉發 國家資安資訊分享與分析中心 資安訊息警訊 NISAC-200-202607-00000002

[內容說明]
研究人員發現pgAdmin 4存在多項高風險安全漏洞(CVE-2026-12044至CVE-2026-12050),其中最嚴重之CVE-2026-12046為不安全反序列化(Insecure Deserialization)漏洞,當產品以伺服器模式運作,且攻擊者已知pgAdmin之Flask SECRET_KEY並具備寫入pgAdmin之Session目錄權限時,可利用此漏洞執行任意程式碼,請儘速確認並進行修補。

[影響平台]
pgAdmin 4之1.0至9.15版本

[建議措施]
官方已針對漏洞釋出修復更新,請參考官方說明進行更新,網址如下: https://www.postgresql.org/about/news/pgadmin-4-v916-released-3324/

[參考資料]
1. https://nvd.nist.gov/vuln/detail/CVE-2026-12044
2. https://nvd.nist.gov/vuln/detail/CVE-2026-12045
3. https://nvd.nist.gov/vuln/detail/CVE-2026-12046
4. https://nvd.nist.gov/vuln/detail/CVE-2026-12047
5. https://nvd.nist.gov/vuln/detail/CVE-2026-12048
6. https://nvd.nist.gov/vuln/detail/CVE-2026-12049
7. https://nvd.nist.gov/vuln/detail/CVE-2026-12050
8. https://www.postgresql.org/about/news/pgadmin-4-v916-released-3324/

Forwarded National Information Security Analysis and Sharing Center Security Advisory Alert NISAC-200-202607-00000002

[Description]
Researchers have discovered multiple high-risk security vulnerabilities in pgAdmin 4 (CVE-2026-12044 to CVE-2026-12050). Among them, the most severe CVE-2026-12046 is an insecure deserialization (Insecure Deserialization) vulnerability. When the product operates in server mode, and the attacker knows the pgAdmin Flask SECRET_KEY and has permission to write to the pgAdmin Session directory, this vulnerability can be exploited to execute arbitrary code. Please confirm and apply patches as soon as possible.

[Affected Platform]
pgAdmin 4 versions 1.0 to 9.15

[Recommendations]
The official has released fixes for the vulnerabilities. Please refer to the official instructions for updates at the following URL: https://www.postgresql.org/about/news/pgadmin-4-v916-released-3324/

[References]
1. https://nvd.nist.gov/vuln/detail/CVE-2026-12044
2. https://nvd.nist.gov/vuln/detail/CVE-2026-12045
3. https://nvd.nist.gov/vuln/detail/CVE-2026-12046
4. https://nvd.nist.gov/vuln/detail/CVE-2026-12047
5. https://nvd.nist.gov/vuln/detail/CVE-2026-12048
6. https://nvd.nist.gov/vuln/detail/CVE-2026-12049
7. https://nvd.nist.gov/vuln/detail/CVE-2026-12050
8. https://www.postgresql.org/about/news/pgadmin-4-v916-released-3324/


相關附件
※為降低附件原始檔案遭搜尋引擎索引之風險,公告附件將由瀏覽器先下載至本機暫存後再開啟。請確認使用環境安全後,再決定是否開啟附件。
Top↑