{"id":"CVE-2026-1707","summary":"Restore restriction bypass via key disclosure vulnerability (pgAdmin 4)","details":"pgAdmin versions 9.11 are affected by a Restore restriction bypass via key disclosure vulnerability that occurs when running in server mode and performing restores from PLAIN-format dump files. An attacker with access to the pgAdmin web interface can observe an active restore operation, extract the `\\restrict` key in real time, and race the restore process by overwriting the restore script with a payload that re-enables meta-commands using `\\unrestrict \u003ckey\u003e`. This results in reliable command execution on the pgAdmin host during the restore operation.","aliases":["GHSA-3p7x-94q9-jq9x","PYSEC-2026-2864"],"modified":"2026-08-14T10:42:13.318791793Z","published":"2026-02-05T17:30:05.089Z","related":["openSUSE-SU-2026:11508-1"],"database_specific":{"cna_assigner":"PostgreSQL","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/1xxx/CVE-2026-1707.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/1xxx/CVE-2026-1707.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-1707"},{"type":"REPORT","url":"https://github.com/pgadmin-org/pgadmin4/issues/9518"},{"type":"PACKAGE","url":"https://github.com/pgadmin-org/pgadmin4"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/pgadmin-org/pgadmin4","events":[{"introduced":"dc801e362ebde7fe59ecf77eaaab740fe7452cc5"},{"last_affected":"dc801e362ebde7fe59ecf77eaaab740fe7452cc5"}],"database_specific":{"source":["AFFECTED_FIELD","CPE_STRING"],"cpe":"cpe:2.3:a:pgadmin:pgadmin_4:9.11:*:*:*:*:postgresql:*:*","extracted_events":[{"introduced":"9.11"},{"last_affected":"9.11"}]}}],"versions":["9.11","REL-9_11"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-1707.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L"}]}