Posting Date: 2026/08/12
【Vulnerability Alert】pgAdmin 4 contains a high-risk security vulnerability (CVE-2026-17566). Please verify and apply patches as soon as possible.
- Subject: 【Vulnerability Alert】pgAdmin 4 contains a high-risk security vulnerability (CVE-2026-17566). Please verify and apply patches as soon as possible.
- Description:
- Forwarded from National Information Sharing and Analysis Center (NISAC) Information Security Alert NISAC-200-202608-00000003
- Researchers have discovered a high-risk OS Command Injection security vulnerability (CVE-2026-17566) in pgAdmin 4. Due to improper handling of SQL queries in pgAdmin 4's Import/Export Data tool, an authenticated remote attacker could exploit this vulnerability to execute arbitrary code. Please verify and apply patches as soon as possible.
- Affected Platforms:
- pgAdmin 4 versions 1.0 through 9.16
- Recommendations:
- The vendor has released patch updates for this vulnerability. Please refer to the official announcement to update, URL as follows: https://www.postgresql.org/about/news/pgadmin-4-v917-released-3356/
- Reference Information:
Computer and Communication Center
Network System Division Sincerely