pgAdmin <= 9.7 is affected by a Cross-Origin Opener Policy (COOP) vulnerability. This vulnerability allows an attacker to manipulate the OAuth flow, potentially leading to unauthorised account access, account takeover, data breaches, and privilege escalation.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://github.com/pgadmin-org/pgadmin4/issues/9114 |
|
History
Thu, 11 Sep 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:pgadmin:pgadmin_4:*:*:*:*:*:postgresql:*:* |
Fri, 05 Sep 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pgadmin
Pgadmin pgadmin Pgadmin pgadmin 4 |
|
| Vendors & Products |
Pgadmin
Pgadmin pgadmin Pgadmin pgadmin 4 |
Thu, 04 Sep 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-346 | |
| Metrics |
ssvc
|
Thu, 04 Sep 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | pgAdmin <= 9.7 is affected by a Cross-Origin Opener Policy (COOP) vulnerability. This vulnerability allows an attacker to manipulate the OAuth flow, potentially leading to unauthorised account access, account takeover, data breaches, and privilege escalation. | |
| Title | Cross-Origin Opener Policy Vulnerability in pgAdmin 4 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: PostgreSQL
Published: 2025-09-04T16:43:27.710Z
Updated: 2025-09-05T03:55:49.451Z
Reserved: 2025-08-28T20:28:18.654Z
Link: CVE-2025-9636
Updated: 2025-09-04T17:12:15.524Z
Status : Analyzed
Published: 2025-09-04T17:15:39.670
Modified: 2025-09-11T21:26:47.250
Link: CVE-2025-9636
No data.