Researchers have discovered an authentication bypass vulnerability (CVE-2026-86863) in pgAdmin 4. When the web server authentication source is enabled, an unauthenticated remote attacker may impersonate any user (including administrators) by sending a specially crafted HTTP request header, thereby obtaining pgAdmin administrative privileges. Please verify and handle promptly.