PatchSiren cyber security CVE debrief
CVE-2026-7815 pgadmin.org CVE debrief
A SQL injection vulnerability in pgAdmin 4's Maintenance Tool allows authenticated users with tools_maintenance permission to execute arbitrary SQL on connected PostgreSQL servers. Four JSON parameters (buffer_usage_limit, vacuum_parallel, vacuum_index_cleanup, reindex_tablespace) were concatenated directly into VACUUM/ANALYZE/REINDEX commands without proper sanitization. Attackers can break out of option syntax and inject SQL, potentially escalating to OS command execution via COPY ... TO PROGRAM. The vulnerability affects pgAdmin 4 versions from 7.6 through 9.14. The fix implements server-side allow-listing for all four fields and applies the qtIdent filter to reindex_tablespace.
- Vendor
- pgadmin.org
- Product
- pgAdmin 4
- CVSS
- HIGH 8.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-11
- Original CVE updated
- 2026-05-26
- Advisory published
- 2026-05-11
- Advisory updated
- 2026-05-26
Who should care
Organizations running pgAdmin 4 versions 7.6 through 9.14 for PostgreSQL database administration, particularly those granting tools_maintenance permissions to non-administrative users or exposing pgAdmin instances to less-trusted networks.
Technical summary
The pgAdmin 4 Maintenance Tool constructs VACUUM, ANALYZE, and REINDEX commands by directly concatenating user-supplied JSON values into psql --command invocations. The vulnerable parameters—buffer_usage_limit, vacuum_parallel, vacuum_index_cleanup, and reindex_tablespace—lack server-side validation or proper identifier quoting. An authenticated attacker with tools_maintenance permission can inject SQL metacharacters to terminate the intended command and execute arbitrary statements. The PostgreSQL COPY ... TO PROGRAM feature enables subsequent operating-system command execution on the database host. The remediation introduces strict allow-list validation for all four fields and replaces manual string concatenation with the qtIdent filter for reindex_tablespace, ensuring proper PostgreSQL identifier quoting.
Defensive priority
HIGH
Recommended defensive actions
- Upgrade pgAdmin 4 to version 9.15 or later
- Restrict tools_maintenance permission to trusted administrative accounts only
- Monitor PostgreSQL query logs for suspicious COPY ... TO PROGRAM statements
- Review database user permissions to limit potential blast radius of compromised pgAdmin accounts
- Apply principle of least privilege for database connections from pgAdmin instances
Evidence notes
CVE published 2026-05-11; NVD entry modified 2026-05-26. Vendor advisory and patch available via GitHub issue #9898. CVSS 4.0 vector confirms network attack vector with low attack complexity, low privileges required, and high impact to confidentiality, integrity, and availability.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-7815 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-7815
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-7815 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-7815
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/pgadmin-org/pgadmin4/issues/9898
f86ef6dc-4d3a-42ad-8f28-e6d5547a5007 - Issue Tracking, Patch, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.