CRITICAL 9.8 CVE-2026-86863 Published 17 Sept 2026

pgAdmin 4 Webserver Authentication Bypass

Worried this affects your website?

pgAdmin 4's Webserver authentication source was vulnerable to bypass due to improper handling of HTTP headers. An attacker could authenticate as any user, including an administrator, without providing credentials.

Affected versions: pgAdmin 4 from 6.2 before 9.18. The vulnerability is mitigated when 'webserver' is not enabled in AUTHENTICATION_SOURCES.

Reference: CVE-2026-86863 on NVD

← Back to Security News