CVE-2026-7819
Last modified
CVE-2026-7819 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. Symbolic-link path traversal (CWE-61, CWE-22) in pgAdmin 4 File Manager. check_access_permission used os.path.abspath, which resolves '..' but does not resolve symbolic links, while the subsequent kernel write follows symlinks. An authenticated user could plant a symbolic link inside their own storage directory pointing outside it and induce pgAdmin to write to any path reachable by the pgAdmin process. Fix switches the access check to os.path.realpath for both source and destination, and adds an _open_upload_target helper that opens the target with O_NOFOLLOW (mode 0o600) to close the leaf-component TOCTOU between the access check and the open. EPSS estimates a 0.36% chance of exploitation in the next 30 days.
Description
Symbolic-link path traversal (CWE-61, CWE-22) in pgAdmin 4 File Manager. check_access_permission used os.path.abspath, which resolves '..' but does not resolve symbolic links, while the subsequent kernel write follows symlinks. An authenticated user could plant a symbolic link inside their own storage directory pointing outside it and induce pgAdmin to write to any path reachable by the pgAdmin process. Fix switches the access check to os.path.realpath for both source and destination, and adds an _open_upload_target helper that opens the target with O_NOFOLLOW (mode 0o600) to close the leaf-component TOCTOU between the access check and the open. File mode is hardened from 0o644 to 0o600. This issue affects pgAdmin 4: before 9.15.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Pgadmin | Pgadmin 4 | < 9.15 |
References
- https://github.com/pgadmin-org/pgadmin4/issues/9902Issue Tracking, Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-7819?
How severe is CVE-2026-7819?
How do I fix CVE-2026-7819?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-7813Authorization vulnerability in pgAdmin 4 server mode affecti…9.9
- CVE-2026-7814Stored cross-site scripting (XSS) vulnerability in pgAdmin 4…4.8
- CVE-2026-7815SQL injection vulnerability in pgAdmin 4 Maintenance Tool. …8.8
- CVE-2026-7816OS command injection (CWE-78) vulnerability in pgAdmin 4 Imp…8.8
- CVE-2026-7817Local file inclusion (LFI) and server-side request forgery (…7.1
- CVE-2026-7818Deserialization of untrusted data (CWE-502) in pgAdmin 4 Fil…7.8
- CVE-2026-7820Improper restriction of excessive authentication attempts (C…6.9
- CVE-2026-7821Improper certificate validation in Ivanti EPMM before versio…9.1
- CVE-2026-7822A vulnerability was identified in itsourcecode Courier Manag…6.3
- CVE-2026-7823A security flaw has been discovered in Totolink A8000RU 7.1c…9.8
- CVE-2026-7824An issue was discovered in the PaperCut Hive Ricoh embedded …5.9
- CVE-2026-7828UltraVNC repeater through 1.8.2.2 contains an integer overfl…5.3
Are you affected by CVE-2026-7819?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
