CVE-2026-7814: pgAdmin 4: Stored XSS via crafted PostgreSQL object names in Browser Tree and Explain Visualizer

Published May 11, 2026
·
Updated

Stored cross-site scripting (XSS) vulnerability in pgAdmin 4 Browser Tree and Explain Visualizer modules.

User-controlled PostgreSQL object names (database, schema, table, column, etc.) were assigned to DOM elements via innerHTML, allowing crafted object names containing HTML markup to execute attacker-supplied JavaScript in the browser of any pgAdmin user who navigated to or executed EXPLAIN over the malicious object.

Fix replaces innerHTML with textContent.

This issue affects pgAdmin 4: before 9.15.

Affected Software

2 affected components
pgAdmin Development Team pgAdmin 4<9.15
pgAdmin Pgadmin 4 Postgresql>=6.9<9.15

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade pgAdmin 4 Browser Tree and Explain Visualizer modules to a version that resolves this vulnerability.

    Fixed in 9.15
  2. Configuration

    Modify the rendering logic for user-controlled PostgreSQL object names in the Browser Tree and Explain Visualizer to use textContent instead of innerHTML to prevent stored XSS.

    pgAdmin 4 Browser Tree and Explain Visualizer DOM assignment method for PostgreSQL object names = innerHTML -> textContent

Event History

May 11, 2026
CVE Published
via MITRE·02:35 PM
Data Sourced
via MITRE·02:35 PM
DescriptionSeverity
Data Sourced
via NVD·04:17 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jun 24, 58372
Event
via FIRST·02:46 AM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-7814?

CVE-2026-7814 is classified as a medium severity vulnerability due to its potential for stored cross-site scripting (XSS) attacks.

2

How do I fix CVE-2026-7814?

To fix CVE-2026-7814, upgrade pgAdmin 4 to version 9.15 or later where the vulnerability has been addressed.

3

What components of pgAdmin 4 are affected by CVE-2026-7814?

CVE-2026-7814 affects the Browser Tree and Explain Visualizer modules of pgAdmin 4.

4

Can CVE-2026-7814 affect user data in pgAdmin 4?

Yes, CVE-2026-7814 can potentially allow attackers to inject malicious scripts that might affect user data by exploiting XSS.

5

Who is responsible for addressing CVE-2026-7814 in pgAdmin 4?

The pgAdmin Development Team is responsible for addressing CVE-2026-7814 and providing updates to mitigate the vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203