CVE-2025-9636
7.9pgAdmin · pgAdmin 4
A Cross-Origin Opener Policy (COOP) vulnerability in pgAdmin 4 versions prior to 9.8 allows attackers to manipulate OAuth flows, potentially leading to unauthorized account access and data breaches.
Executive summary
A critical vulnerability in pgAdmin 4 allows attackers to exploit OAuth flows, resulting in unauthorized account access and potential privilege escalation.
Vulnerability
This is a Cross-Origin Opener Policy (COOP) misconfiguration that affects the OAuth authentication process. The vulnerability requires a low-privileged authenticated user to interact with a malicious site, which then facilitates the manipulation of the authentication flow.
Business impact
Successful exploitation of this flaw can lead to full account takeover, unauthorized access to database management interfaces, and significant data breaches. Given the CVSS score of 7.9, this vulnerability represents a high risk to organizational confidentiality and integrity, as it provides a pathway for lateral movement within database environments.
Remediation
Immediate Action: Update pgAdmin 4 to version 9.8 or later immediately to resolve the COOP misconfiguration.
Proactive Monitoring: Review web access logs for unusual patterns involving OAuth callback endpoints or unexpected cross-origin requests originating from administrative sessions.
Compensating Controls: Ensure that strict Content Security Policy (CSP) headers are enforced, and advise users to remain cautious of phishing attempts that might lead them to malicious sites during active management sessions.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The severity of this vulnerability, combined with the potential for total account compromise, necessitates prompt action. Administrators should verify the current version of their pgAdmin instances and deploy the 9.8 update as part of their next maintenance cycle to eliminate this risk.
More pgAdmin CVEs
History
- Disclosed CVE record published
- Published in the daily brief high section
- Published in the daily brief high section
- Published in the daily brief high section
- Analyst report written
- Fix documented version 9.8 per CVE record