【資安漏洞預警】pgAdmin 4存在高風險安全漏洞(CVE-2026-86863),請儘速確認並進行處置
【Security Vulnerability Alert】pgAdmin 4 has a high-risk security vulnerability (CVE-2026-86863), please confirm and take action as soon as possible

發布單位:圖資處網路系統組
日期範圍:2026/10/8 ~ 2027/4/8
 
發布單位:圖資處網路系統組
日期範圍:2026/10/8 ~ 2027/4/8
行政 行政公告
全體

轉發 國家資安資訊分享與分析中心 資安訊息警訊 NISAC-200-202610-00000006

[內容說明]
研究人員發現pgAdmin 4存在身分鑑別繞過(Authentication Bypass)漏洞(CVE-2026-86863),當啟用Webserver身分鑑別來源時,未經身分鑑別之遠端攻擊者可藉由傳送特製HTTP請求標頭冒充任意使用者(包含管理者),進而取得pgAdmin管理權限,請儘速確認並進行處置。

[影響平台]
pgAdmin 4之6.2至9.17版本

[建議措施]
官方已針對漏洞釋出修補或更新,請參考官方說明進行處置,網址如下: https://github.com/pgadmin-org/pgadmin4/issues/10383

[參考資料]
1. https://nvd.nist.gov/vuln/detail/CVE-2026-86863
2. https://github.com/pgadmin-org/pgadmin4/issues/10383

Forwarded National Information and Analysis Center for Cyber Security Cybersecurity Information Alert NISAC-200-202610-00000006

[Description]
Researchers have discovered an Authentication Bypass vulnerability (CVE-2026-86863) in pgAdmin 4. When the Webserver authentication source is enabled, an unauthenticated remote attacker can impersonate any user (including administrators) by sending specially crafted HTTP request headers, thereby obtaining pgAdmin administrative privileges. Please confirm and take action as soon as possible.

[Affected Platforms]
pgAdmin 4 versions 6.2 to 9.17

[Recommended Measures]
The vendor has released patches or updates for the vulnerability. Please refer to the official instructions for remediation. The URL is as follows: https://github.com/pgadmin-org/pgadmin4/issues/10383

[References]
1. https://nvd.nist.gov/vuln/detail/CVE-2026-86863
2. https://github.com/pgadmin-org/pgadmin4/issues/10383


相關附件
※為降低附件原始檔案遭搜尋引擎索引之風險,公告附件將由瀏覽器先下載至本機暫存後再開啟。請確認使用環境安全後,再決定是否開啟附件。
system_update_alt參考資料1
system_update_alt參考資料2
Top↑