Impact
The flaw allows a client to convince the pgAdmin 4 Webserver authentication mode to accept any user identity supplied in a custom HTTP header. The code mistakenly treats the header value as a trusted identity instead of a genuine WSGI environment variable, permitting authentication as, for example, an existing Administrator without any password. This falls under broken authentication weaknesses and leads to full credential impersonation.
Affected Systems
pgAdmin 4 deployed with authentication sources including 'webserver', affecting all versions from 6.2 up to but not including 9.18. The vulnerability applies only when the Webserver authentication mode is active, regardless of other authentication sources.
Risk and Exploitability
The exploit is trivial for a remote attacker who can reach the pgAdmin web interface; they can forge the required header and gain arbitrary user access without any credentials. If the application is publicly reachable, the likelihood of exploitation is high. The risk remains elevated until the installation is updated to a version that implements the guardrails described in the fix – namely, requiring a shared secret, validating proxy trust, and ensuring only CGI-derived environment variables are used for authentication.
OpenCVE Enrichment