CVE-2026-7819
Last modified
CVE-2026-7819 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. Symbolic-link path traversal (CWE-61, CWE-22) in pgAdmin 4 File Manager. check_access_permission used os.path.abspath, which resolves '..' but does not resolve symbolic links, while the subsequent kernel write follows symlinks. An authenticated user could plant a symbolic link inside their own storage directory pointing outside it and induce pgAdmin to write to any path reachable by the pgAdmin process. Fix switches the access check to os.path.realpath for both source and destination, and adds an _open_upload_target helper that opens the target with O_NOFOLLOW (mode 0o600) to close the leaf-component TOCTOU between the access check and the open. EPSS estimates a 0.36% chance of exploitation in the next 30 days.
Description
Symbolic-link path traversal (CWE-61, CWE-22) in pgAdmin 4 File Manager. check_access_permission used os.path.abspath, which resolves '..' but does not resolve symbolic links, while the subsequent kernel write follows symlinks. An authenticated user could plant a symbolic link inside their own storage directory pointing outside it and induce pgAdmin to write to any path reachable by the pgAdmin process. Fix switches the access check to os.path.realpath for both source and destination, and adds an _open_upload_target helper that opens the target with O_NOFOLLOW (mode 0o600) to close the leaf-component TOCTOU between the access check and the open. File mode is hardened from 0o644 to 0o600. This issue affects pgAdmin 4: before 9.15.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Pgadmin | Pgadmin 4 | < 9.15 |
References
- https://github.com/pgadmin-org/pgadmin4/issues/9902Issue Tracking, Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-7819?
How severe is CVE-2026-7819?
How do I fix CVE-2026-7819?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-78181A weakness has been identified in ractivejs ractive up to 1.…7.3
- CVE-2026-78182A security vulnerability has been detected in Shenzhen Gongj…7.3
- CVE-2026-78183DBD::Pg version 3.21.0 for Perl has a heap out-of-bounds wri…9.8
- CVE-2026-78185A vulnerability was detected in itsourcecode Sales and Inven…6.3
- CVE-2026-78186A flaw has been found in Open5GS up to 2.8.0. This affects a…4.3
- CVE-2026-78187A vulnerability has been found in Piwigo 16.3.0. This impact…3.1
- CVE-2026-78195Rejected reason: Rejecting as a duplicate of CVE-2026-78047
- CVE-2026-78196A security flaw has been discovered in achorein expo-share-i…4.4
- CVE-2026-78197A weakness has been identified in SourceCodester Simple Onli…7.3
- CVE-2026-78198A security vulnerability has been detected in SourceCodester…7.3
- CVE-2026-78199A vulnerability was detected in SourceCodester Simple Online…7.3
- CVE-2026-7820Improper restriction of excessive authentication attempts (C…6.9
Are you affected by CVE-2026-7819?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
