CVE-2022-4223High· 8.8▾ MidnightPoC availablepgadmin4 vulnerable to Code Injection
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 48.4 · likelihood 16 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
80%
80% → 80%
Nuclei ×1
The pgAdmin server includes an HTTP API that is intended to be used to validate the path a user selects to external PostgreSQL utilities such as pg_dump and pg_restore. The utility is executed by the server to determine what PostgreSQL version it is from. Versions of pgAdmin prior to 6.17 failed to properly secure this API, which could allow an unauthenticated user to call it with a path of their choosing, such as a UNC path to a server they control on a Windows machine. This would cause an appropriately named executable in the target path to be executed by the pgAdmin server.
pgadmin4 < 6.17Upgrade to a patched release:
pgadmin4 6.17Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2024-9014High· 8.6OAuth2 client ID and secret exposed through the web browser
CVE-2024-3116High· 7.4pgAdmin Remote Code Execution (RCE) vulnerability
CVE-2026-7813Critical· 9.9pgAdmin 4 server mode has an authorization vulnerability affecting Server Groups, Servers, Shared Servers, Background Processes, and Debu…
CVE-2026-7817Medium· 6.5pgAdmin 4 contains local file inclusion (LFI) and server-side request forgery (SSRF) vulnerabilities
CVE-2026-7816High· 8.8pgAdmin 4: OS command injection vulnerability in Import/Export query export
CVE-2026-7820Medium· 6.5pgAdmin 4: Improper restriction of excessive authentication attempts