Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-86861

Gravedad CVSS v4.0:
MEDIA
Tipo:
CWE-59 Incorrecta resolución de una ruta antes de aceder a un fichero (Seguimiento de enlaces)
Fecha de publicación:
17/09/2026
Última modificación:
21/09/2026

Descripción

*** Pendiente de traducción *** pgAdmin 4&amp;#39;s File Manager save_file endpoint, which backs saving from the Query Tool and ERD, validated the requested path with Filemanager.check_access_permission() and then opened the file for writing with a plain open() call. CVE-2026-7819 had previously hardened the separate file upload path by opening its target with O_NOFOLLOW, so that the kernel refuses to follow a symbolic link at the final path component, but save_file was left on an unprotected open(). A symbolic link already present when the check ran was rejected by the check itself; the remaining exposure was a link substituted at the final path component in the interval between the check and the write, at which point the write followed the link and landed outside the user&amp;#39;s storage directory, creating or overwriting an arbitrary file as the operating-system account running pgAdmin.<br /> <br /> Exploitation requires the ability to create or replace a symbolic link inside the requesting user&amp;#39;s storage directory. pgAdmin exposes no interface that creates symbolic links, so this requires filesystem access to the pgAdmin host or to a shared or network-mounted storage backend, together with winning the timing window. The reporter did not achieve a write against a released version, having attempted approximately 63,000 racing requests without success; the reported defect is the uncovered write path rather than a demonstrated sandbox escape.<br /> <br /> The fix routes save_file&amp;#39;s write through the same O_NOFOLLOW-protected helper already used by the upload path, so both File Manager write sinks carry identical kernel-enforced protection, and reports a symbolic-link refusal explicitly instead of surfacing the underlying system error text. Note that files created by save_file are now given mode 0600, inheriting the behaviour introduced for uploads. The protection covers the final path component; substitution of an intermediate directory component is not addressed by this change.<br /> <br /> This issue affects pgAdmin 4: from the introduction of the containment check in the File Manager save path before 9.18.

Productos y versiones vulnerables

CPE Desde Hasta
cpe:2.3:a:pgadmin:pgadmin_4:*:*:*:*:*:postgresql:*:* 9.18 (excluyendo)


Referencias a soluciones, herramientas e información