CVE-2026-17347: pgAdmin 4: OS command injection in MASTER_PASSWORD_HOOK via untrusted username substitution

Published Jul 31, 2026
·
Updated

The MASTERPASSWORDHOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an external command that returns a per-user encryption key, with %u in the configured string replaced by the current user's name. The previous implementation substituted the username directly into the command string and executed the result with subprocess.Popen(..., shell=True). Because the username can originate from an external authentication source (OAuth/OIDC claims, Kerberos, webserver auth) rather than a value pgAdmin fully controls, a username containing shell metacharacters (';', '$()', backticks, pipes, '&&', newlines) allowed an authenticated user to execute arbitrary commands as the pgAdmin service account in any deployment where the configured hook string uses %u.

Fix tokenises the trusted, administrator-configured hook string into an argument vector first (using shlex in POSIX-quoting mode, with backslash-escaping disabled so Windows-style paths are not mis-parsed), substitutes the untrusted username into the individual argv elements, and executes with shell=False. The username is therefore always confined to a single argv element; any shell metacharacters it contains are inert. Administrators whose MASTERPASSWORDHOOK previously relied on shell features (pipes, redirection, environment-variable expansion, globbing) within the hook string itself must move that logic into the invoked script, since it is no longer interpreted by a shell.

This issue affects pgAdmin 4: from 7.2 before 9.17.

Affected Software

2 affected components
pgAdmin pgAdmin 4>=7.2<9.17
pgAdmin Pgadmin 4 Postgresql>=7.2<9.17

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade pgAdmin 4 to a version that resolves this vulnerability.

    Fixed in 9.17
  2. Operational

    If you previously used MASTER_PASSWORD_HOOK with %u, review and update the hook configuration so that any logic that depended on shell features (pipes, redirection, environment-variable expansion, globbing) is moved into the invoked script, since the hook string is tokenised and executed with shell=False in newer implementations.

Event History

Jul 31, 2026
CVE Published
via MITRE·03:59 PM
Data Sourced
via MITRE·03:59 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-17347?

CVE-2026-17347 has a severity rating of 7.5, classified as high.

2

How do I fix CVE-2026-17347?

To mitigate CVE-2026-17347, ensure that the MASTER_PASSWORD_HOOK setting is not using untrusted user input.

3

What causes CVE-2026-17347?

CVE-2026-17347 is caused by OS command injection vulnerabilities due to untrusted username substitution in the MASTER_PASSWORD_HOOK setting.

4

What software is affected by CVE-2026-17347?

CVE-2026-17347 affects pgAdmin 4 version 7.2 and later.

5

What should I do if I am using a vulnerable version with CVE-2026-17347?

If using a vulnerable version, it is recommended to upgrade to the latest pgAdmin 4 version where the vulnerability is fixed.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203