pgAdmin 4 v9.18 Ships Four Security Fixes
pgAdmin 4 v9.18 shipped today, bundling 29 changes with four freshly patched vulnerabilities, all credited to outside researchers. The most serious, CVE-2026-86863, is an authentication bypass in Webserver mode that lets anyone assert any identity, including admins, without a credential. Two more CVEs close repeated injection holes in the Backup and Restore tools by routing database names through PGDATABASE instead of libpq's connection-string expansion. Alongside a much-welcomed VS Code-style Object Explorer toggle, the release also refreshes core dependencies and is strongly advised for every server-mode deployment.
pgAdmin 4 v9.18 Ships Four Security Fixes @ Linux Compatible
pgAdmin 4 v9.18 Ships Four Security Fixes
pgAdmin 4 v9.18 has been released, addressing four security vulnerabilities identified by external researchers, including a serious authentication bypass that allows unauthorized identity assertion. The release also fixes two injection vulnerabilities in the Backup and Restore tools, as well as a symlink path traversal issue in the File Manager. Additionally, a new feature resembling a VS Code-style Object Explorer toggle has been introduced, alongside updates to core dependencies. Users are strongly advised to upgrade to this version, especially if running pgAdmin in server mode, to mitigate risks associated with the recently patched vulnerabilities
