CVE-2025-12762 is a critical Remote Code Execution (RCE) vulnerability affecting pgAdmin versions up to 9.9 when operating in server mode and restoring from PLAIN-format dump files. This allows unauthenticated attackers to execute arbitrary commands on the pgAdmin server, posing a severe risk to data integrity and system security. With a CVSS score of 9.8 (CRITICAL), it is easily exploitable over the network with no user interaction required, leading to complete compromise of confidentiality, integrity, and availability. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion, indicating awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 9.10CPE matchmatch criteria | cpe:2.3:a:pgadmin:pgadmin_4:*:*:*:*:*:postgresql:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.