← Zurück zur CVE-Suche

CVE-2026-7820

pgAdmin

Beschreibung

Improper restriction of excessive authentication attempts (CWE-307) in pgAdmin 4. pgAdmin enforces MAX_LOGIN_ATTEMPTS only inside its custom /authenticate/login view. Flask-Security-s default /login view, which is registered automatically by security.init_app() and is reachable on every server, never consulted the User.locked field: pgAdmin-s User model relied on Flask-Security-s UserMixin.is_locked() (which always returns -not locked-) and Flask-Login-s is_active (which only checks the active column, not locked). An attacker who triggered an account lockout via /authenticate/login could therefore obtain a session by re-submitting valid credentials directly to /login, defeating the brute-force-protection control for accounts using the INTERNAL authentication source. The same bypass also means that login attempts via /login are never rate-limited, so an attacker can perform an unbounded online password-guessing attack against INTERNAL accounts regardless of MAX_LOGIN_ATTEMPTS. Fix overr...

CVSS 6.5EPSS 0.211%Risiko 0.66
Quelle öffnen
Veröffentlicht
2026-05-11 16:17:39
Betroffene Versionen
<9.15
Typ
Core software
Vektor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N