CVE-2026-17347: pgAdmin 4: OS command injection in MASTER_PASSWORD_HOOK via untrusted username substitution
The MASTERPASSWORDHOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an external command that returns a per-user encryption key, with %u in the configured string replaced by the current user's name. The previous implementation substituted the username directly into the command string and executed the result with subprocess.Popen(..., shell=True). Because the username can originate from an external authentication source (OAuth/OIDC claims, Kerberos, webserver auth) rather than a value pgAdmin fully controls, a username containing shell metacharacters (';', '$()', backticks, pipes, '&&', newlines) allowed an authenticated user to execute arbitrary commands as the pgAdmin service account in any deployment where the configured hook string uses %u.
Fix tokenises the trusted, administrator-configured hook string into an argument vector first (using shlex in POSIX-quoting mode, with backslash-escaping disabled so Windows-style paths are not mis-parsed), substitutes the untrusted username into the individual argv elements, and executes with shell=False. The username is therefore always confined to a single argv element; any shell metacharacters it contains are inert. Administrators whose MASTERPASSWORDHOOK previously relied on shell features (pipes, redirection, environment-variable expansion, globbing) within the hook string itself must move that logic into the invoked script, since it is no longer interpreted by a shell.
This issue affects pgAdmin 4: from 7.2 before 9.17.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pgAdmin 4to a version that resolves this vulnerability.Fixed in 9.17 - Operational
If you previously used MASTER_PASSWORD_HOOK with %u, review and update the hook configuration so that any logic that depended on shell features (pipes, redirection, environment-variable expansion, globbing) is moved into the invoked script, since the hook string is tokenised and executed with shell=False in newer implementations.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-17347?
CVE-2026-17347 has a severity rating of 7.5, classified as high.
How do I fix CVE-2026-17347?
To mitigate CVE-2026-17347, ensure that the MASTER_PASSWORD_HOOK setting is not using untrusted user input.
What causes CVE-2026-17347?
CVE-2026-17347 is caused by OS command injection vulnerabilities due to untrusted username substitution in the MASTER_PASSWORD_HOOK setting.
What software is affected by CVE-2026-17347?
CVE-2026-17347 affects pgAdmin 4 version 7.2 and later.
What should I do if I am using a vulnerable version with CVE-2026-17347?
If using a vulnerable version, it is recommended to upgrade to the latest pgAdmin 4 version where the vulnerability is fixed.