Threat reportVulnerabilityTL-2026-0900
pgAdmin 4 v9.16 Patches 7 Vulnerabilities (CVE-2026-12044 to CVE-2026-12050): SQLi, AI-Assistant Read-Only Bypass to RCE, Auth Bypass with Pickle Deserialization, Stored XSS
pgAdmin 4 v9.16 Patches 7 Vulnerabilities (CVE-2026-12044 to (TL-2026-0900) is a high-severity software vulnerability scored CVSS 9, first published 2026-06-22. It has no confirmed attribution, affects pgAdmin Development Team (PostgreSQL Global Development Group) pgAdmin, references 7 CVEs (CVE-2026-12044, CVE-2026-12045, CVE-2026-12046), maps to 19 MITRE ATT&CK techniques (T1059, T1059.004, T1059.007), and is covered by 9 detection rules and 22 indicators of compromise.
- CVSS
- 9/10High
- CVEs
- 7Referenced vulnerabilities
- Techniques
- 19MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 22Indicators of compromise
Key facts for TL-2026-0900
- Threat ID
- TL-2026-0900
- Severity
- HIGH
- CVSS
- 9 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- UNKNOWN
- Target sectors
- technology, financial, government, healthcare, enterprise IT / database administration
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 22
Malware and tooling in pgAdmin 4 v9.16 Patches 7 Vulnerabilities (CVE-2026-12044 to
Malware and tooling: pgAdmin AI Assistant
How pgAdmin 4 v9.16 Patches 7 Vulnerabilities (CVE-2026-12044 to works
pgAdmin 4 v9.16 fixes seven vulnerabilities (CVE-2026-12044 through CVE-2026-12050) in the widely deployed PostgreSQL administration tool. The most severe is an AI Assistant read-only transaction bypass (CVE-2026-12045) that lets prompt-injected multi-statement SQL escape the READ ONLY wrapper and chain to OS command execution via COPY ... TO PROGRAM on a superuser connection. The release also addresses SQL injection across sixteen dialog templates, an authentication bypass exposing a pickle deserialization sink, a critical stored XSS that can exfiltrate saved server credentials, HTML injection, an MFA open redirect, and a second SQLi in the named restore point endpoint.
On June 18-19, 2026 the pgAdmin Development Team (under the PostgreSQL Global Development Group) released pgAdmin 4 v9.16, bundling 64 bug fixes with patches for seven security vulnerabilities tracked as CVE-2026-12044 through CVE-2026-12050. pgAdmin 4 is the most popular open-source administration and development platform for PostgreSQL, deployed both as a desktop application and in multi-user 'server mode' web deployments inside enterprises and cloud environments, which broadens the attack surface for several of these issues.
CVE-2026-12044 (SQL injection, CVSS ~8.8 HIGH) affected sixteen dialog templates that rendered COMMENT ON ... IS '<description>' statements. Object names or descriptions containing apostrophes or crafted input broke out of the string literal, allowing injection. The fix migrates the affected templates to qtLiteral() for safe quoting and rewrites statistics calls to pass the relation OID via a ::oid::regclass cast instead of interpolating identifiers.
CVE-2026-12045 (AI Assistant read-only transaction bypass to RCE, CVSS ~9.0 CRITICAL) is the highest-impact issue. The AI Assistant feature wrapped generated queries in a READ ONLY transaction as a guardrail, but prompt-injected multi-statement payloads could commit outside that wrapper and execute arbitrary SQL. On a connection running with superuser privileges this chains to operating-system command execution through PostgreSQL's COPY ... TO PROGRAM functionality. Because the assistant can be steered by content it reads from the database, an attacker who can influence database content (rows, object comments, error text) can manipulate the assistant into executing write/exec operations the operator never intended.
CVE-2026-12046 (authentication bypass / unsafe deserialization) is an access-control failure in server mode: two SQL Editor endpoints were missing the @pga_login_required decorator, leaving a pickle deserialization sink reachable without authentication. Unauthenticated access to a Python pickle deserialization path is a classic remote-code-execution risk. The fix enforces login validation on all affected endpoints.
CVE-2026-12047 (HTML injection) occurs in the cloud-deployment modules (Amazon RDS, Microsoft Azure, Google Cloud) where SDK exception text was rendered unsanitized through html-react-parser, allowing markup injection into the browser DOM.
CVE-2026-12048 (critical stored XSS) is the broadest client-side issue: PostgreSQL server error text and EXPLAIN plan-node content were passed unsanitized through html-react-parser across notifier toasts, form errors, modal alerts, and the Explain visualizer. A malicious server, or attacker-controlled query plan/error text, could execute script in the pgAdmin operator's session, exfiltrate saved server credentials, and issue SQL against any connected server.
CVE-2026-12049 (open redirect) is an unvalidated 'next' parameter in the multi-factor authentication flow that can redirect a user to an attacker-chosen URL, useful for phishing and credential-harvesting pretexts.
CVE-2026-12050 (SQL injection) is in the named restore point endpoint, where the user-supplied restore point name was interpolated into SQL via str.format() instead of bound parameters; the fix uses parameterized queries.
There is no public reporting of in-the-wild exploitation at disclosure, and no published proof-of-concept exploit; the mechanics are documented in the vendor release notes and security press. The dominant risk profile is privileged-but-authenticated misuse (AI Assistant, SQLi, restore point), malicious-server / hostile-content attacks (stored XSS, HTML injection), and an unauthenticated server-mode deserialization sink (CVE-2026-12046). Enterprises running shared server-mode pgAdmin should treat CVE-2026-12045 and CVE-2026-12046 as priority and upgrade to v9.16 immediately.
MITRE ATT&CK techniques used in TL-2026-0900
Execution
T1059 Command and Scripting Interpreter; T1059.004 Unix Shell; T1059.007 JavaScript; T1204.001 Malicious Link
Privilege Escalation
T1068 Exploitation for Privilege Escalation; T1078 Valid Accounts; T1548 Abuse Elevation Control Mechanism
Command and Control
Collection
T1185 Browser Session Hijacking; T1213 Data from Information Repositories
Initial Access
T1190 Exploit Public-Facing Application; T1566 Phishing
Defense Evasion
T1211 Exploitation for Stealth
Credential Access
T1212 Exploitation for Credential Access; T1539 Steal Web Session Cookie; T1552.001 Credentials In Files
Impact
T1565.001 Stored Data Manipulation
Exfiltration
T1567 Exfiltration Over Web Service
defense-impairment
Affected products and versions in pgAdmin 4 v9.16 Patches 7 Vulnerabilities (CVE-2026-12044 to
- pgAdmin Development Team (PostgreSQL Global Development Group) — pgAdmin 4
Vulnerable versions: < 9.16 (versions prior to 9.16, desktop and server/web mode)
Fixed in: 9.16
Remediation for pgAdmin 4 v9.16 Patches 7 Vulnerabilities (CVE-2026-12044 to
Patches
- pgAdmin 4 v9.16 (issues #10078, #10022, #10072, #10069, #10068, #10028, #10026)
Immediate actions
- Upgrade all pgAdmin 4 deployments to v9.16 or later; this is the only complete fix for all seven CVEs.
- Prioritize multi-user server-mode web deployments, which are exposed to the unauthenticated pickle deserialization sink (CVE-2026-12046) and stored XSS (CVE-2026-12048).
- Until patched, restrict the AI Assistant feature and avoid using it against connections that hold superuser privileges (mitigates CVE-2026-12045 RCE chain).
Workarounds
- Disable the AI Assistant integration where it is not required.
- Avoid connecting pgAdmin to untrusted/hostile PostgreSQL servers, which could deliver malicious error text or EXPLAIN content (CVE-2026-12048 / CVE-2026-12047).
- Restrict access to server-mode pgAdmin endpoints to authenticated, trusted users only.
Longer-term hardening
- Run pgAdmin database connections with least-privilege roles rather than superuser to break the COPY ... TO PROGRAM RCE chain.
- Place server-mode pgAdmin behind authenticated reverse proxies / network segmentation and never expose it directly to the internet.
- Disable or strictly control COPY ... TO PROGRAM at the PostgreSQL layer (limit to trusted superusers; consider revoking pg_execute_server_program).
CVEs associated with pgAdmin 4 v9.16 Patches 7 Vulnerabilities (CVE-2026-12044 to
CVE-2026-12044, CVE-2026-12045, CVE-2026-12046, CVE-2026-12047, CVE-2026-12048, CVE-2026-12049, CVE-2026-12050
Weaknesses (CWE) in pgAdmin 4 v9.16 Patches 7 Vulnerabilities (CVE-2026-12044 to
CWE-89, CWE-79, CWE-80, CWE-502, CWE-306, CWE-601, CWE-78, CWE-863, CWE-1427, CWE-94
Timeline of pgAdmin 4 v9.16 Patches 7 Vulnerabilities (CVE-2026-12044 to
- v9.16 also removed the administrator-role bypass from the server-access helpers (issue #9933) so the access-control checks added in v9.15 for CVE-2026-7813 are now enforced uniformly, closing a prior server-mode authorization gap.
- pgAdmin 4 v9.16 release notes published, documenting fixes for CVE-2026-12044 through CVE-2026-12050 (issues #10078, #10022, #10072, #10069, #10068, #10028, #10026) alongside 64 bug fixes.
- The seven vulnerabilities were responsibly disclosed to the pgAdmin Development Team by external researchers credited in the release notes: Jasser Chebbi (CVE-2026-12044), Isaac Chen (CVE-2026-12045), Fernando Bortotti (CVE-2026-12046/12047/12048), Mai Pham Hien (CVE-2026-12049), and Geo (CVE-2026-12050).
- The PostgreSQL Global Development Group published the official pgAdmin 4 v9.16 release announcement on postgresql.org, the authoritative fixed-version reference.
- No public proof-of-concept exploit and no reports of in-the-wild exploitation at time of disclosure; risk profile is privileged misuse, hostile-server content, and an unauthenticated server-mode deserialization sink.
- pgAdmin 4 v9.16 available for download as the remediation for all seven vulnerabilities; upgrade recommended for enterprise/server-mode deployments.
- CVE identifiers CVE-2026-12044 through CVE-2026-12050 assigned and associated with pgAdmin 4 versions prior to 9.16.
- Security press (Cyber Security News, Cyberpress, SecureReading) reported the seven CVEs, detailing the AI Assistant read-only bypass to RCE via COPY ... TO PROGRAM and the critical stored XSS.
Sources cited for pgAdmin 4 v9.16 Patches 7 Vulnerabilities (CVE-2026-12044 to
Detection coverage for TL-2026-0900
As of 2026-06-22, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0900 across Splunk SPL, Microsoft KQL and Sigma, covering 22 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.