← Back to browse · API

CVE-2024-3116

Severity
HIGH
CVSS
7.4
EPSS
0.64846
Risk score
52.3
CISA KEV
No
PoC
No
Published
2024-04-04
Modified
2025-03-14
First seen
2026-08-07
Aliases
EUVD-2024-1054, GHSA-27JX-FFW8-XRQV, PYSEC-2026-1767
Products
pgadmin.org:pgAdmin 4, pgadmin.org:pgAdmin 4 0 <8.5
Sources
euvd EUVD-2024-1054

Description

pgAdmin <= 8.4 is affected by a Remote Code Execution (RCE) vulnerability through the validate binary path API. This vulnerability allows attackers to execute arbitrary code on the server hosting PGAdmin, posing a severe risk to the database management system's integrity and the security of the underlying data.

References