{"id":"CVE-2026-17347","summary":"pgAdmin 4: OS command injection in MASTER_PASSWORD_HOOK via untrusted username substitution","details":"The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an external command that returns a per-user encryption key, with %u in the configured string replaced by the current user's name. The previous implementation substituted the username directly into the command string and executed the result with subprocess.Popen(..., shell=True). Because the username can originate from an external authentication source (OAuth/OIDC claims, Kerberos, webserver auth) rather than a value pgAdmin fully controls, a username containing shell metacharacters (';', '$()', backticks, pipes, '&&', newlines) allowed an authenticated user to execute arbitrary commands as the pgAdmin service account in any deployment where the configured hook string uses %u.\n\nFix tokenises the trusted, administrator-configured hook string into an argument vector first (using shlex in POSIX-quoting mode, with backslash-escaping disabled so Windows-style paths are not mis-parsed), substitutes the untrusted username into the individual argv elements, and executes with shell=False. The username is therefore always confined to a single argv element; any shell metacharacters it contains are inert. Administrators whose MASTER_PASSWORD_HOOK previously relied on shell features (pipes, redirection, environment-variable expansion, globbing) within the hook string itself must move that logic into the invoked script, since it is no longer interpreted by a shell.\n\nThis issue affects pgAdmin 4: from 7.2 before 9.17.","modified":"2026-08-14T10:42:12.947128925Z","published":"2026-07-31T15:59:16.588Z","related":["openSUSE-SU-2026:11508-1"],"database_specific":{"cna_assigner":"PostgreSQL","cwe_ids":["CWE-78","CWE-88"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/17xxx/CVE-2026-17347.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/17xxx/CVE-2026-17347.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-17347"},{"type":"REPORT","url":"https://github.com/pgadmin-org/pgadmin4/issues/10191"},{"type":"FIX","url":"https://github.com/pgadmin-org/pgadmin4/commit/e7a85767314e7b0fe0b35fe80b9c1af38f48dff6"},{"type":"FIX","url":"https://github.com/pgadmin-org/pgadmin4/commit/ea7e798aac27174d2bacee1d6e136bed76a95e23"},{"type":"PACKAGE","url":"https://github.com/pgadmin-org/pgadmin4"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/pgadmin-org/pgadmin4","events":[{"introduced":"7dfcc73e958fa5c04282b02ffc5eb10d83bacc47"},{"fixed":"067f7af2274cf034623426d2b74a7695018a5f1f"},{"fixed":"e7a85767314e7b0fe0b35fe80b9c1af38f48dff6"},{"fixed":"ea7e798aac27174d2bacee1d6e136bed76a95e23"}],"database_specific":{"cpe":"cpe:2.3:a:pgadmin:pgadmin_4:*:*:*:*:*:postgresql:*:*","extracted_events":[{"introduced":"7.2"},{"fixed":"9.17"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["REL-9_16","REL-9_15","REL-9_14","REL-9_13","REL-9_12","REL-9_11","REL-9_10","REL-9_9","REL-9_8","REL-9_7","REL-9_6","REL-9_5","REL-9_4","REL-9_3","REL-9_2","REL-9_1","REL-9_0","REL-8_14","REL-8_13","REL-8_12","REL-8_11","REL-8_10","REL-8_9","REL-8_8","REL-8_7","REL-8_6","REL-8_5","REL-8_4","REL-8_3","REL-8_2","REL-8_1","REL-8_0","REL-7_8","REL-7_7","REL-7_6","REL-7_5","REL-7_4","REL-7_3","REL-7_2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-17347.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}