Home

Description

pgAdmin versions 9.11 are affected by a Restore restriction bypass via key disclosure vulnerability that occurs when running in server mode and performing restores from PLAIN-format dump files. An attacker with access to the pgAdmin web interface can observe an active restore operation, extract the `\restrict` key in real time, and race the restore process by overwriting the restore script with a payload that re-enables meta-commands using `\unrestrict <key>`. This results in reliable command execution on the pgAdmin host during the restore operation.

PUBLISHED Reserved 2026-01-30 | Published 2026-02-05 | Updated 2026-02-06 | Assigner PostgreSQL




HIGH: 7.4CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L

Product status

Default status
unaffected

9.11 (custom)
affected

References

github.com/pgadmin-org/pgadmin4/issues/9518 issue-tracking

cve.org (CVE-2026-1707)

nvd.nist.gov (CVE-2026-1707)

Download JSON