CVE-2026-12050 | pgAdmin 4 up to 9.15 restore_point str.format sql injection (Issue 10026 / WID-SEC-2026-2005)
A vulnerability has been found in pgAdmin 4 up to 9.15 and classified as critical. The impacted element is the function str.format of the file /browser/server/restore_point. Performing a manipulation results in sql injection.
This vulnerability is identified as CVE-2026-12050. The attack can be initiated remotely. There is not any exploit available.
The affected component should be upgraded.