CVE-2026-7819HIGH 8.1EPSS p25.6%

CVE-2026-7819CVE-2026-7819

Description

Symbolic-link path traversal (CWE-61, CWE-22) in pgAdmin 4 File Manager. check_access_permission used os.path.abspath, which resolves '..' but does not resolve symbolic links, while the subsequent kernel write follows symlinks. An authenticated user could plant a symbolic link inside their own storage directory pointing outside it and induce pgAdmin to write to any path reachable by the pgAdmin process. Fix switches the access check to os.path.realpath for both source and destination, and adds an _open_upload_target helper that opens the target with O_NOFOLLOW (mode 0o600) to close the leaf-component TOCTOU between the access check and the open. File mode is hardened from 0o644 to 0o600. This issue affects pgAdmin 4: before 9.15.

Scoring

CVSS 3.18.1 (HIGH)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
EPSS0.34% probability of exploitation · percentile 25.6% · 2026-06-19T12:03:05Z
Published2026-05-11
Last modified2026-05-26

Underlying weaknesses· 1

CWE-61

References

  1. https://github.com/pgadmin-org/pgadmin4/issues/9902

1

TypeTargetConfidenceTier
WeaknessUNIX Symbolic Link (Symlink) Followingcwe-610%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2026-7816
CVE
CVE-2025-12763
CVE
CVE-2026-6475
CVE
CVE-2026-7815
CVE
CVE-2026-11419
CVE
CVE-2026-7813
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.