CVE-2026-7816

OS command injection (CWE-78) vulnerability in pgAdmin 4 Import/Export query export. User-supplied input was interpolated directly into a psql \copy metacommand template without sanitization. An authenticated user could inject ") TO PROGRAM 'cmd'" to break out of the \copy (...) context and achieve arbitrary command execution on the pgAdmin server, or ") TO '/path'" for arbitrary file write. Additional fields (format, on_error, log_verbosity) were also raw-interpolated and exploitable. Fix adds a parens-balance parser modeled on psql's strtokx tokenizer, allow-lists format/on_error/log_verbosity, rejects null bytes in the query, and tightens type and gating checks. This issue affects pgAdmin 4: before 9.15.
References
Link Resource
https://github.com/pgadmin-org/pgadmin4/issues/9899 Issue Tracking Patch Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:pgadmin:pgadmin_4:*:*:*:*:*:postgresql:*:*

History

No history.

Information

Published : 2026-05-11 16:17

Updated : 2026-06-17 11:02


NVD link : CVE-2026-7816

Mitre link : CVE-2026-7816

CVE.ORG link : CVE-2026-7816


JSON object : View

Products Affected

pgadmin

  • pgadmin_4
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')