Description
The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an external command that returns a per-user encryption key, with %u in the configured string replaced by the current user's name. The previous implementation substituted the username directly into the command string and executed the result with subprocess.Popen(..., shell=True). Because the username can originate from an external authentication source (OAuth/OIDC claims, Kerberos, webserver auth) rather than a value pgAdmin fully controls, a username containing shell metacharacters (';', '$()', backticks, pipes, '&&', newlines) allowed an authenticated user to execute arbitrary commands as the pgAdmin service account in any deployment where the configured hook string uses %u.

Fix tokenises the trusted, administrator-configured hook string into an argument vector first (using shlex in POSIX-quoting mode, with backslash-escaping disabled so Windows-style paths are not mis-parsed), substitutes the untrusted username into the individual argv elements, and executes with shell=False. The username is therefore always confined to a single argv element; any shell metacharacters it contains are inert. Administrators whose MASTER_PASSWORD_HOOK previously relied on shell features (pipes, redirection, environment-variable expansion, globbing) within the hook string itself must move that logic into the invoked script, since it is no longer interpreted by a shell.

This issue affects pgAdmin 4: from 7.2 before 9.17.
Published: 2026-07-31
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The MASTER_PASSWORD_HOOK setting in pgAdmin 4, used between versions 7.2 and 9.17, expands a %u placeholder with the logged‑in user’s name before executing the resulting command string via subprocess.Popen with shell=True. Because the username can originate from external authentication sources such as OAuth, OIDC claims, Kerberos, or web‑server authentication, an attacker can supply a name containing shell meta‑characters. The original implementation’s direct substitution and shell execution thus allowed arbitrary command execution as the pgAdmin service account, a classic OS command injection (CWE‑78). This fault permits full compromise of the host where pgAdmin runs.

Affected Systems

The vulnerable product is pgAdmin 4. Any deployment running versions from 7.2 up to, but not including, 9.17 that uses the MASTER_PASSWORD_HOOK setting with %u substitution is affected. This includes installations that accept user names from external authentication providers such as OAuth, OIDC, Kerberos, or web‑server auth.

Risk and Exploitability

With a CVSS score of 7.7 the vulnerability is classified as high severity. The EPSS score of less than 1 % indicates a low expected exploitation probability, and it is not currently listed in the CISA KEV catalogue. Nonetheless, the flaw enables a remote authenticated user to execute arbitrary commands as the pgAdmin service account, delivering catastrophic impact if the hook string is enabled. The attack requires the attacker to be authenticated to pgAdmin and to leverage a configuration that expands %u with an untrusted username.

Generated by OpenCVE AI on August 2, 2026 at 04:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade pgAdmin 4 to version 9.17 or later, which tokenises the hook string and executes it with shell disabled.
  • Ensure that the MASTER_PASSWORD_HOOK configuration no longer relies on shell features such as pipes or redirects; if shell logic is needed, move it into the invoked script itself.
  • Limit supplied usernames to trusted authentication sources and validate or sanitise the username value before it is passed to the hook to prevent injection attacks.

Generated by OpenCVE AI on August 2, 2026 at 04:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Pgadmin
Pgadmin pgadmin 4
Vendors & Products Pgadmin
Pgadmin pgadmin 4

Fri, 31 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 31 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Description The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an external command that returns a per-user encryption key, with %u in the configured string replaced by the current user's name. The previous implementation substituted the username directly into the command string and executed the result with subprocess.Popen(..., shell=True). Because the username can originate from an external authentication source (OAuth/OIDC claims, Kerberos, webserver auth) rather than a value pgAdmin fully controls, a username containing shell metacharacters (';', '$()', backticks, pipes, '&&', newlines) allowed an authenticated user to execute arbitrary commands as the pgAdmin service account in any deployment where the configured hook string uses %u. Fix tokenises the trusted, administrator-configured hook string into an argument vector first (using shlex in POSIX-quoting mode, with backslash-escaping disabled so Windows-style paths are not mis-parsed), substitutes the untrusted username into the individual argv elements, and executes with shell=False. The username is therefore always confined to a single argv element; any shell metacharacters it contains are inert. Administrators whose MASTER_PASSWORD_HOOK previously relied on shell features (pipes, redirection, environment-variable expansion, globbing) within the hook string itself must move that logic into the invoked script, since it is no longer interpreted by a shell. This issue affects pgAdmin 4: from 7.2 before 9.17.
Title pgAdmin 4: OS command injection in MASTER_PASSWORD_HOOK via untrusted username substitution
Weaknesses CWE-78
CWE-88
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Pgadmin Pgadmin 4
cve-icon MITRE

Status: PUBLISHED

Assigner: PostgreSQL

Published:

Updated: 2026-08-01T03:56:12.755Z

Reserved: 2026-07-25T02:52:54.844Z

Link: CVE-2026-17347

cve-icon Vulnrichment

Updated: 2026-07-31T17:23:34.759Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-31T16:16:59.140

Modified: 2026-08-07T17:42:20.840

Link: CVE-2026-17347

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T19:15:17Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

  • CWE-88

    Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')