Impact
pgweb through 0.17.0 allows an attacker to send an unauthenticated POST request to /api/connect when connection‑backend authorization is active. The request can carry any database connection string and a custom session identifier, bypassing the intended resource‑to‑database mapping. As a result the attacker can gain access to databases and internal services that should be protected, potentially exposing confidential data or executing malicious queries.
Affected Systems
This issue affects the pgweb web‑based database manager developed by sosedoff, specifically releases up through and including version 0.17.0. Any instance running this version without proper network isolation is vulnerable.
Risk and Exploitability
The vulnerability scores a CVSS of 8.4, indicating high severity, and its EPSS score is below 1 %. The lack of authentication on the endpoint provides a direct remote exploitation path: any host that can reach the pgweb service can send the malicious request. The issue is not listed in the CISA KEV catalog, but if an instance is exposed to untrusted networks the impact can be significant.
OpenCVE Enrichment