CVE-2026-17351: pgAdmin 4: AI Assistant read-only transaction bypass via sqlparse/PostgreSQL lexer disagreement (incomplete fix for CVE-2026-12045)

Published Jul 31, 2026
·
Updated

The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's executesqlquery tool to parse, via sqlparse, as exactly one non-transaction-control statement before running it inside a BEGIN TRANSACTION READ ONLY wrapper. sqlparse's string-literal lexing can disagree with PostgreSQL's own parser: under standardconformingstrings = on (PostgreSQL's default since 9.1), a backslash immediately before a quote is an ordinary character to PostgreSQL, but sqlparse treats it as escaping the quote. A payload such as SELECT '\';COMMIT;CREATE TABLE pwn(x int);SELECT 1 --' therefore parses as a single SELECT to sqlparse's validator, while PostgreSQL executes it as four statements: the smuggled COMMIT ends the wrapping read-only transaction, and the trailing ROLLBACK becomes a no-op. This reintroduces the same write/RCE bypass CVE-2026-12045 was meant to close, reachable via the same indirect prompt-injection delivery (an attacker plants the payload in any object the AI Assistant may read; the LLM emits it as a tool call).

An initial candidate fix ran the query with psycopg's execute(..., prepare=True), intending to force PostgreSQL's own Parse step (extended query protocol) to reject multi-statement text regardless of sqlparse's classification. This candidate fix does not work as submitted: psycopg3's PrepareManager silently ignores the prepare argument whenever the connection's preparethreshold is None, which is pgAdmin's default for every server connection (the per-server "Prepare threshold" field is blank unless an administrator explicitly sets it) -- psycopg3 falls back to the simple query protocol, the same multi-statement-capable path the bypass exploits, so the candidate fix closes nothing on any real-world default configuration.

The corrected fix sets conn.preparethreshold = 0 directly on the dedicated, single-use read-only connection the AI Assistant tool opens, structurally forcing the extended query protocol independent of any server-level configuration. Verified against a live PostgreSQL 18 instance: the payload executes successfully under the preparethreshold=None (default) behavior, and is rejected with "cannot insert multiple commands into a prepared statement" once preparethreshold=0 is set on that connection.

This issue affects pgAdmin 4: from 9.13 before 9.17.

Affected Software

2 affected components
pgAdmin pgAdmin 4>9.13<=9.17
pgAdmin Pgadmin 4 Postgresql>=9.13<9.17

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Set conn.prepare_threshold = 0 on the dedicated, single-use read-only connection used by the AI Assistant tool, so PostgreSQL uses the extended query protocol and rejects multi-statement text (fix verified: payload is rejected with "cannot insert multiple commands into a prepared statement" when prepare_threshold=0, and executes successfully when prepare_threshold=None).

    pgAdmin 4 AI Assistant tool (execute_sql_query / PostgreSQL connection) prepare_threshold = 0

Event History

Jul 31, 2026
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-17351?

CVE-2026-17351 has a critical severity rating of 9.

2

How do I fix CVE-2026-17351?

Fixing CVE-2026-17351 involves upgrading to the latest version of pgAdmin 4 that includes the complete fix.

3

What is the impact of CVE-2026-17351?

CVE-2026-17351 allows a read-only transaction bypass, potentially leading to unauthorized access to sensitive data.

4

What software is affected by CVE-2026-17351?

CVE-2026-17351 affects pgAdmin 4, specifically related to its AI Assistant functionality.

5

Is CVE-2026-17351 related to CVE-2026-12045?

Yes, CVE-2026-17351 is an incomplete fix for the issue originally identified in CVE-2026-12045.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203