目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2026-17348— pgAdmin 4 SERVER模式认证缺失致未授权访问

CVSS 6.5 · Medium

Affected Version Matrix 3

ベンダープロダクトVersion Rangeステータス
pgadmin.orgpgAdmin 41.0< 9.17affected
4.18< 9.17affected
8.2< 9.17affected
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2026-17348の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
pgAdmin 4: Missing authentication decorator on Constraints, preferences, Debugger and Schema Diff routes allows unauthenticated access in SERVER mode (incomplete fix for CVE-2026-12046)
ソース: CVE Program / CVE List V5
脆弱性説明
In SERVER mode, pgAdmin 4 enforces authentication per route via the @pga_login_required decorator; the application's before_request hook only handles desktop-mode auto-login and the Kerberos/Webserver-auth redirect, so any route shipped without the decorator is reachable without authentication (CWE-306). This is the same defect class previously fixed as CVE-2026-12046 (the sqleditor close/update_connection routes). A follow-up sweep, prompted by a report describing an incomplete fix for CVE-2026-12046, found further routes missing @pga_login_required: the Constraints blueprint's nodes and proplist (object listing) routes and its delete route (a state-mutating DELETE that removes table constraints); preferences.get_all_cli (GET, discloses all CLI-settable preference values); debugger.close (DELETE); and schema_diff.close (DELETE). An unauthenticated network client could therefore enumerate constraint metadata, delete table constraints, read preference values, and force-close debugger or schema-diff sessions belonging to other users, without ever authenticating. Fix adds the missing @pga_login_required decorator (and the corresponding import to the Constraints module) to each of these routes. The change is decorator-only; no behavioral changes to the underlying handlers. This issue affects pgAdmin 4 in SERVER mode: the Constraints and Debugger routes from 1.0, the Schema Diff close route from 4.18, and preferences.get_all_cli from 8.2, all before 9.17.
ソース: CVE Program / CVE List V5
CVSS情報
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
ソース: CVE Program / CVE List V5
脆弱性タイプ
关键功能的认证机制缺失
ソース: CVE Program / CVE List V5

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
pgadmin.orgpgAdmin 4 1.0 ~ 9.17 -
pgadmin.orgpgAdmin 4 4.18 ~ 9.17 -
pgadmin.orgpgAdmin 4 8.2 ~ 9.17 -

II. CVE-2026-17348の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2026-17348のインテリジェンス情報

登录查看更多情报信息。

CVE-2026-17348 补丁与修复 (1)

CVE-2026-17348 厂商安全公告 (1)

Same Patch Batch · pgadmin.org · 2026-07-31 · 7 CVEs total

CVE-2026-175669.9 CRITICALpgAdmin 4: RCE via backslash-escape mismatch in Import/Export Data query guard (incomplete
CVE-2026-173499.6 CRITICALpgAdmin 4: Adhoc server clone leaks another user's stored database credentials and ownersh
CVE-2026-173519.0 CRITICALpgAdmin 4: AI Assistant read-only transaction bypass via sqlparse/PostgreSQL lexer disagre
CVE-2026-173468.8 HIGHpgAdmin 4: SQL injection via unescaped object names in index Statistics and publication/su
CVE-2026-173477.5 HIGHpgAdmin 4: OS command injection in MASTER_PASSWORD_HOOK via untrusted username substitutio
CVE-2026-173505.4 MEDIUMpgAdmin 4: Tool permission bypass via backend routes and Socket.IO handlers

IV. 関連脆弱性

V. CVE-2026-17348へのコメント

まだコメントはありません


コメントを残す