CVE-2026-17350 | pgadmin-org pgAdmin up to 9.16 Socket IO adhoc_connect_server has_permission user_id/shared privileges management

SecurityVulns

A vulnerability categorized as critical has been discovered in pgadmin-org pgAdmin up to 9.16. This issue affects the function has_permission of the file /misc/workspace/adhoc_connect_server of the component Socket IO Handler. The manipulation of the argument user_id/shared results in improper privilege management.

This vulnerability is reported as CVE-2026-17350. The attack can be launched remotely. No exploit exists.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More