
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-1707 is a restore restriction bypass via key disclosure vulnerability in pgAdmin 4 version 9.11, affecting deployments running in server mode. When performing restores from PLAIN-format dump files, the \restrict key used to disable psql meta-commands is exposed in the process watcher, allowing an authenticated attacker to extract it in real time and race the restore process to achieve command execution on the pgAdmin host. The vulnerability was disclosed on February 5, 2026, and is patched in pgAdmin 4 version 9.12. It carries a CVSS v3.1 base score of 6.3 (Medium) per NVD, or 7.4 (High) per the GitHub Advisory Database with a changed scope vector (Github Advisory, Red Hat Bugzilla).
The root cause is a combination of improper access control (CWE-284) and authorization bypass through user-controlled key (CWE-639): when pgAdmin initiates a restore from a PLAIN-format SQL dump in server mode, it passes a \restrict key to psql to disable meta-commands, but this key is visible in the process watcher interface accessible to authenticated web users. An attacker can observe the running restore operation, extract the secret \restrict key from the process watcher in real time, and then race the restore by overwriting the restore script on disk with a payload that calls \unrestrict <key> to re-enable meta-commands, followed by arbitrary psql meta-commands (e.g., \! for OS command execution). The fix, tracked in pgAdmin issue #9518, involves masking the secret key in the process watcher output so it cannot be observed by users (Github Advisory, pgAdmin Issue, Red Hat Bugzilla).
Successful exploitation allows an authenticated attacker with low privileges to execute arbitrary OS commands on the pgAdmin host system during an active restore operation, resulting in low-to-moderate impacts on confidentiality, integrity, and availability. Because the commands execute in the context of the pgAdmin server process, an attacker could read sensitive files, modify data, install backdoors, or disrupt service on the host. The vulnerability is particularly dangerous in multi-user server mode deployments where multiple low-privilege users share access to the pgAdmin web interface (Github Advisory, Red Hat Bugzilla).
There is no public proof-of-concept exploit or evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.021–0.028%, placing it in the 9th percentile for exploitation likelihood within 30 days. No threat actor attribution has been reported, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation requires network access, low privileges (authenticated web interface access), and timing to race an active restore operation, which somewhat limits opportunistic exploitation (Github Advisory, Feedly).
\restrict key: Observe the process watcher output for the running restore operation. The secret key passed to psql via the \restrict directive is visible in the process arguments or watcher display in the vulnerable version.\unrestrict <extracted_key> followed by \! <OS command> to re-enable and execute meta-commands./bin/sh, bash, curl, wget, python) during or immediately after a restore operation; psql processes executing commands not consistent with a normal restore.The vulnerability is patched in pgAdmin 4 version 9.12, which masks the \restrict secret key in the process watcher output (Github Advisory, pgAdmin Issue). Organizations unable to upgrade immediately should: (1) restrict network access to the pgAdmin web interface to trusted users and networks only; (2) minimize the number of accounts with web interface access; (3) avoid performing PLAIN-format dump restores in server mode from untrusted sources; (4) monitor and log all restore operations for anomalous activity; and (5) consider disabling restore functionality if not actively required. Fedora packages have also received updates addressing this CVE.
Red Hat tracked the vulnerability as high severity in their Bugzilla system and published a security advisory. The pgAdmin project addressed the issue under milestone 9.12, with the fix committed to the pgadmin4 repository. Fedora issued security advisories for pgadmin4 packages on both Fedora 43 and current Fedora releases. Tenable added detection for the vulnerability in their plugin pipeline, and Qualys included it in their February 2026 application security detections. Coverage has been limited to security aggregators and Linux distribution advisories, with no notable broader media or social media discussion (Red Hat Bugzilla, Github Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."