← Back to browse · API

CVE-2024-9014

Severity
CRITICAL
CVSS
9.9
EPSS
0.09685
Risk score
42.99
CISA KEV
No
PoC
No
Published
2024-09-23
Modified
2024-09-23
First seen
2026-08-07
Aliases
EUVD-2024-2825, GHSA-JM9X-RX9X-WPQJ, PYSEC-2026-1775
Products
pgadmin.org:pgAdmin 4 0 <8.12
Sources
euvd EUVD-2024-2825

Description

pgAdmin versions 8.11 and earlier are vulnerable to a security flaw in OAuth2 authentication. This vulnerability allows an attacker to potentially obtain the client ID and secret, leading to unauthorized access to user data.

References