Researchers have discovered a high-risk
OS Command Injection security vulnerability (CVE-2026-17566) in pgAdmin 4. Due to improper handling of SQL queries in pgAdmin 4's Import/Export Data tool, an authenticated remote attacker could exploit this vulnerability to execute arbitrary code. Please verify and apply patches as soon as possible.