CVE-2025-9636

pgAdmin <= 9.7 is affected by a Cross-Origin Opener Policy (COOP) vulnerability. This vulnerability allows an attacker to manipulate the OAuth flow, potentially leading to unauthorised account access, account takeover, data breaches, and privilege escalation.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:pgadmin:pgadmin_4:*:*:*:*:*:postgresql:*:*

History

11 Sep 2025, 21:26

Type Values Removed Values Added
First Time Pgadmin pgadmin 4
Pgadmin
CPE cpe:2.3:a:pgadmin:pgadmin_4:*:*:*:*:*:postgresql:*:*
References () https://github.com/pgadmin-org/pgadmin4/issues/9114 - () https://github.com/pgadmin-org/pgadmin4/issues/9114 - Issue Tracking

04 Sep 2025, 18:15

Type Values Removed Values Added
CWE CWE-346

04 Sep 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-04 17:15

Updated : 2025-09-11 21:26


NVD link : CVE-2025-9636

Mitre link : CVE-2025-9636

CVE.ORG link : CVE-2025-9636


JSON object : View

Products Affected

pgadmin

  • pgadmin_4
CWE
CWE-346

Origin Validation Error