PatchSiren cyber security CVE debrief
CVE-2026-17350 pgadmin.org CVE debrief
The CVE-2026-17350 vulnerability affects pgAdmin 4 in SERVER mode, specifically the per-tool permission system which did not consistently enforce permission checks. This allowed authenticated users with explicit permission denials to bypass tool-level access controls. The issue was introduced in version 9.3 and fixed in version 9.17. Users should review and update their installations to mitigate this vulnerability. The vulnerability has a CVSS score of 5.3 and a severity of MEDIUM.
- Vendor
- pgadmin.org
- Product
- pgAdmin 4
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-31
- Original CVE updated
- 2026-07-31
- Advisory published
- 2026-07-31
- Advisory updated
- 2026-07-31
Who should care
pgAdmin 4 users and administrators, especially those using SERVER mode, should review and update their installations to version 9.17 or later to mitigate this vulnerability. Additionally, users should verify user permissions and access controls, monitor for suspicious activity, and implement compensating controls to restrict access to sensitive features if necessary. Security teams should also review the vulnerability and assess their exposure to it. Operators of pgAdmin 4 instances should prioritize updating to the latest version to prevent exploitation of this vulnerability. Vulnerability management teams should track this vulnerability and ensure that affected systems are remediated promptly. Platform administrators should also review the vulnerability and take necessary actions to protect their systems. Compensating controls, such as restricting access to sensitive features, may be necessary for systems that cannot be updated immediately. Monitoring and detection capabilities should be reviewed to ensure that potential exploitation can be detected. Asset inventory management should be used to track systems that may be affected by this vulnerability. Rollback and change window management processes should be used to ensure that updates can be applied with minimal disruption. Source tracking and incident response planning should also be reviewed to ensure that organizations are prepared to respond to potential exploitation of this vulnerability. Security teams should also review and update their incident response plans to include this vulnerability. Overall, a comprehensive review of the vulnerability and its potential impact on the organization is necessary to ensure that appropriate measures are taken to mitigate the risk. This includes reviewing the vulnerability management process, change management process, and incident response plan to ensure that they are effective in addressing this type of vulnerability. By taking these steps, organizations can reduce the risk of exploitation and protect their systems from potential attacks. The vulnerability management process should be reviewed to ensure that it is effective in identifying and remediating this type.
Technical summary
The per-tool permission system in pgAdmin 4 did not consistently enforce permission checks, allowing authenticated users with explicit permission denials to bypass tool-level access controls. The issue affects pgAdmin 4 in SERVER mode from version 9.3 before 9.17. The vulnerability was caused by the permission decorator being applied only to a single 'front door' route per tool, while other backend routes and Socket.IO handlers relied solely on authentication checks. The fix adds a socket_permissions_required decorator and applies it to all backend routes and Socket.IO handlers for the affected tools.
Defensive priority
Authenticated users with explicit permission denials for specific pgAdmin 4 tools could bypass tool-level access controls, accessing features they were intended to be withheld from, without gaining additional database privileges.
Recommended defensive actions
- Review and update pgAdmin 4 to version 9.17 or later
- Verify user permissions and access controls
- Monitor for suspicious activity
- Implement compensating controls to restrict access to sensitive features
- Review and update incident response plans to include this vulnerability
- Use asset inventory management to track systems that may be affected by this vulnerability
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The per-tool permission system in pgAdmin 4 did not consistently enforce permission checks. An authenticated user with a valid login and working database connection, but explicitly denied a specific tool's permission, could still use that tool through other routes and sockets. The issue affects pgAdmin 4 in SERVER mode from version 9.3 before 9.17.
Official resources
-
CVE-2026-17350 CVE record
CVE.org
-
CVE-2026-17350 NVD detail
NVD
-
Source item URL
nvd_modified
-
Source reference
f86ef6dc-4d3a-42ad-8f28-e6d5547a5007
-
Source reference
f86ef6dc-4d3a-42ad-8f28-e6d5547a5007
-
Source reference
f86ef6dc-4d3a-42ad-8f28-e6d5547a5007
-
Source reference
f86ef6dc-4d3a-42ad-8f28-e6d5547a5007
-
Source reference
f86ef6dc-4d3a-42ad-8f28-e6d5547a5007
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-31T16:16:59.617Z and has not been modified since then.