---
schema: 1
kind: vulnerability
title: "CVE-2026-12046 / CVE-2026-12045 / CVE-2026-12048 — pgAdmin 4: unauthenticated pickle deserialization RCE, AI-Assistant read-only-transaction bypass, stored XSS"
headline: "CVE-2026-12046 / CVE-2026-12045 / CVE-2026-12048 — pgAdmin 4: unauthenticated pickle deserialization RCE, AI-Assistant read-only-transaction bypass, stored XSS"
summary: "pgAdmin 4 ships an unauthenticated pickle.loads() RCE primitive and an AI-Assistant read-only-transaction bypass (CVE-2026-12046 / CVE-2026-12045, CVSS 9.5 / 9.4), patched in v9.16 (pgAdmin, 2026-06-18)."
discovered_at: "2026-06-19T05:20:55Z"
event_date: 2026-06-18
run_id: 2026-06-19-c306b105
priority: high
immediate_action: null
tags:
  - vulnerabilities
  - rce
  - pre-auth
  - ai-abuse
  - patch-available
regions:
  - global
  - europe
sectors:
  - public-sector
  - education
  - finance
entities: []
cves:
  - id: CVE-2026-12046
    cvss: "9.5"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status:
      - patch-available
  - id: CVE-2026-12045
    cvss: "9.4"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status:
      - patch-available
  - id: CVE-2026-12048
    cvss: "9.3"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status:
      - patch-available
sources:
  - url: "https://www.pgadmin.org/docs/pgadmin4/9.16/release_notes_9_16.html"
    publisher: pgAdmin release notes
    role: primary
  - url: "https://euvd.enisa.europa.eu/enisa/EUVD-2026-37966"
    publisher: ENISA EUVD
    role: corroborating
closed_sources: []
evidence: []
verification: multi-source
sourcing_note: null
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions: []
migrated_from: briefs/2026-06-19.md
---

pgAdmin 4 v9.16 (2026-06-18) patches seven CVEs across v6.0–9.15 in the project's own coordinated-disclosure release notes ([pgAdmin, 2026-06-18](https://www.pgadmin.org/docs/pgadmin4/9.16/release_notes_9_16.html)). CVE-2026-12046 (CVSS v4 9.5): two SQL-Editor endpoints (`DELETE /sqleditor/close/<trans_id>` and `POST /sqleditor/initialize/sqleditor/update_connection/...`) are missing the `@pga_login_required` decorator in server mode, making them reachable unauthenticated; both reach a `pickle.loads()` sink on session `gridData[trans_id]['command_obj']`. Full RCE additionally requires knowledge of the Flask `SECRET_KEY` and write access to the session store — preconditions that can exist on shared hosting or after partial compromise. CVE-2026-12045 (CVSS v4 9.4): the AI Assistant wraps LLM-generated SQL in `BEGIN TRANSACTION READ ONLY`, but a `COMMIT`/`ROLLBACK`-prefixed multi-statement payload escapes the read-only guard, enabling DML and — on a superuser role via `COPY ... TO PROGRAM` — OS command execution, delivered through prompt injection into any database object the Assistant reads. CVE-2026-12048 (CVSS v4 9.3): stored XSS via unsanitised PostgreSQL error text and EXPLAIN-plan content rendered through `html-react-parser`. The pgAdmin release notes do not publish CVSS scores; the CVSS v4 figures here are ENISA EUVD's (EUVD-2026-37966 = 9.5, EUVD-2026-37965 = 9.4, EUVD-2026-37968 = 9.3) ([ENISA EUVD, 2026-06-18](https://euvd.enisa.europa.eu/enisa/EUVD-2026-37966)). No exploitation reported.
