Jump to the main content block

【Vulnerability Alert】pgAdmin 4 Contains Multiple High-Risk Security Vulnerabilities (CVE-2026-12044 to CVE-2026-12050). Please Confirm and Apply Patches as Soon as Possible

publish date : 2026-07-17 update date : 2026-07-17

Source: Ministry of education information & communication security contingency platform

"" "" ""

Publication Number TACERT-ANA-2026071609071414 Publication Time 2026-07-16 09:47:14
Incident Type ANA-Vulnerability Alert Discovery Time 2026-07-16 09:47:14
Impact Level Middle  
[Subject]
【Vulnerability Alert】pgAdmin 4 Contains Multiple High-Risk Security Vulnerabilities (CVE-2026-12044 to CVE-2026-12050). Please Confirm and Apply Patches as Soon as Possible
[Content]

Forwarded from the National Institute of Cyber Security Cybersecurity Alert NISAC-200-202607-00000002

Researchers discovered that pgAdmin 4 contains multiple high-risk security vulnerabilities (CVE-2026-12044 to CVE-2026-12050). The most severe vulnerability, CVE-2026-12046, is an Insecure Deserialization vulnerability. When the product operates in server mode, and an attacker knows pgAdmin's Flask SECRET_KEY and has permission to write to pgAdmin's Session directory, the attacker may exploit this vulnerability to execute arbitrary code. Please confirm and apply patches as soon as possible.

Information Sharing Level: WHITE (the intelligence content is information that may be publicly disclosed)

[Affected Platform]

pgAdmin 4 versions 1.0 to 9.15

[Recommended Actions]

The official vendor has released remediation updates for the vulnerabilities. Please refer to the official instructions for updating. The URL is as follows: https://www.postgresql.org/about/news/pgadmin-4-v916-released-3324/

[Reference]

1. https://nvd.nist.gov/vuln/detail/CVE-2026-12044
2. https://nvd.nist.gov/vuln/detail/CVE-2026-12045
3. https://nvd.nist.gov/vuln/detail/CVE-2026-12046
4. https://nvd.nist.gov/vuln/detail/CVE-2026-12047
5. https://nvd.nist.gov/vuln/detail/CVE-2026-12048
6. https://nvd.nist.gov/vuln/detail/CVE-2026-12049
7. https://nvd.nist.gov/vuln/detail/CVE-2026-12050
8. https://www.postgresql.org/about/news/pgadmin-4-v916-released-3324/

(This notification is for informational purposes only and does not constitute a cybersecurity incident).
If you have questions or suggestions regarding this notification, please feel free to contact us.
Ministry of education information & communication security contingency platform
Website: https://info.cert.tanet.edu.tw/
Phone: +886-7-5250211
Internet Phone: 98400000
E-Mail: service@cert.tanet.edu.tw
Organizer: Computer Center
Click Num: