CVE-2026-7817
Last modified
CVE-2026-7817 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. Local file inclusion (LFI) and server-side request forgery (SSRF) vulnerabilities in pgAdmin 4 LLM API configuration endpoints. User-supplied api_key_file and api_url preferences were passed to the LLM provider clients without validation. An authenticated user could read arbitrary server-side files by pointing api_key_file at any path readable by the pgAdmin process, or coerce pgAdmin into making requests to internal targets (e.g. EPSS estimates a 0.22% chance of exploitation in the next 30 days.
Description
Local file inclusion (LFI) and server-side request forgery (SSRF) vulnerabilities in pgAdmin 4 LLM API configuration endpoints. User-supplied api_key_file and api_url preferences were passed to the LLM provider clients without validation. An authenticated user could read arbitrary server-side files by pointing api_key_file at any path readable by the pgAdmin process, or coerce pgAdmin into making requests to internal targets (e.g. cloud metadata services such as 169.254.169.254) by setting api_url, exploiting the chat path and model-list endpoints. Fix restricts api_key_file to the user's private storage (server mode) or home directory (desktop mode), enforces a printable-ASCII key shape and a 1024-byte read cap, and gates api_url against a configurable allow-list (config.ALLOWED_LLM_API_URLS) at every entry point. This issue affects pgAdmin 4: before 9.15.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Pgadmin | Pgadmin 4 | >= 9.13, < 9.15 |
References
- https://github.com/pgadmin-org/pgadmin4/issues/9900Issue Tracking, Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-7817?
How severe is CVE-2026-7817?
How do I fix CVE-2026-7817?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-78160A vulnerability has been found in Dolibarr ERP up to 18.0.10…6.3
- CVE-2026-78161A vulnerability was found in warmcat libwebsockets 4.5.0. Im…7.3
- CVE-2026-78166A security flaw has been discovered in provectus kafka-ui up…6.3
- CVE-2026-78167A weakness has been identified in EFM ipTIME T16000M 14.20.2…10
- CVE-2026-78168A security vulnerability has been detected in EFM ipTIME T24…9.8
- CVE-2026-78169A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7…9.9
- CVE-2026-78170A flaw has been found in UTT HiPER 1200GW up to 2.5.3-170306…8.8
- CVE-2026-78171A vulnerability has been found in itsourcecode Sales and Inv…7.3
- CVE-2026-78172The Themify – WooCommerce Product Filter plugin for WordPres…6.1
- CVE-2026-78174WatchGuard Dimension records unredacted session identifiers …9.3
- CVE-2026-78175The Tutor LMS – eLearning and online course solution plugin …8.8
- CVE-2026-78177A vulnerability was found in TanStack devtools-vite 0.7.0. A…4.5
Are you affected by CVE-2026-7817?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
