CVE-2026-7815: pgAdmin 4: SQL injection in Maintenance tool option values leading to remote code execution

Published May 11, 2026
·
Updated

SQL injection vulnerability in pgAdmin 4 Maintenance Tool.

Four user-supplied JSON fields (bufferusagelimit, vacuumparallel, vacuumindexcleanup, reindextablespace) were concatenated directly into the rendered VACUUM/ANALYZE/REINDEX command and passed to psql --command. An authenticated user with the toolsmaintenance permission could break out of the option syntax and execute arbitrary SQL on the connected PostgreSQL server. The injected SQL could in turn invoke COPY ... TO PROGRAM to escalate to operating-system command execution on the database host.

Fix introduces server-side allow-listing of all four fields and switches reindextablespace from manual quoting to the qtIdent filter.

This issue affects pgAdmin 4: before 9.15.

Affected Software

2 affected components
pgAdmin pgAdmin 4<9.15
pgAdmin Pgadmin 4 Postgresql>=7.6<9.15

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade pgAdmin 4 Maintenance tool (SQL injection in option values) to a version that resolves this vulnerability.

    Fixed in 9.15
  2. Configuration

    Apply the fix so that the four user-supplied JSON fields (buffer_usage_limit, vacuum_parallel, vacuum_index_cleanup, reindex_tablespace) are allow-listed server-side and not concatenated directly into rendered VACUUM/ANALYZE/REINDEX commands.

    pgAdmin 4 Maintenance tool server-side allow-listing of JSON fields (buffer_usage_limit, vacuum_parallel, vacuum_index_cleanup, reindex_tablespace) = Enabled (allow-list all four fields)
  3. Configuration

    Apply the fix so reindex_tablespace switches from manual quoting to the qtIdent filter when building the REINDEX command.

    pgAdmin 4 Maintenance tool reindex_tablespace quoting behavior = Use qtIdent filter instead of manual quoting

Event History

May 11, 2026
CVE Published
via MITRE·02:35 PM
Data Sourced
via MITRE·02:35 PM
DescriptionSeverity
Data Sourced
via NVD·04:17 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jun 23, 58372
Event
via FIRST·08:42 AM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-7815?

The severity of CVE-2026-7815 is rated as high with a score of 8.7.

2

How do I fix CVE-2026-7815?

To fix CVE-2026-7815, you should apply the available patch for pgAdmin 4 as soon as possible.

3

What type of vulnerability is CVE-2026-7815?

CVE-2026-7815 is an SQL injection vulnerability that can lead to remote code execution.

4

Who is affected by CVE-2026-7815?

Authenticated users of pgAdmin 4 who utilize the Maintenance Tool are affected by CVE-2026-7815.

5

What could an attacker achieve by exploiting CVE-2026-7815?

An attacker exploiting CVE-2026-7815 could potentially execute arbitrary commands on the server, leading to remote code execution.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203