THREAT OPS › Threat News › [NVD] CVE-2026-17346 (HIGH 8.8) — The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT ON / pgstattuple / pgstatindex templates to it, but missed several sinks that had been placed in test_sql_string_literal_lint.py's ALLOWLIST on the incorrect assumption that schema, table
[NVD] CVE-2026-17346 (HIGH 8.8) — The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT ON / pgstattuple / pgstatindex templates to it, but missed several sinks that had been placed in test_sql_string_literal_lint.py's ALLOWLIST on the incorrect assumption that schema, table
CVE-2026-17346 CVSS: 8.8 HIGH Published: 2026-07-31T16:16:58.970
The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT ON / pgstattuple / pgstatindex templates to it, but missed several sinks that had been placed in test_sql_string_literal_lint.py's ALLOWLIST on the incorrect assumption that schema, table, publication, and subscription names sourced from pg_
Indicators of compromise
- CVE-2026-17346cve
- CVE-2026-12044cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-17346