7.9
/ 10
HIGH
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:L
Description
pgAdmin <= 9.7 is affected by a Cross-Origin Opener Policy (COOP) vulnerability. This vulnerability allows an attacker to manipulate the OAuth flow, potentially leading to unauthorised account access, account takeover, data breaches, and privilege escalation.
Basic Information
ID
CVE-2025-9636
Source
PostgreSQL
Published
Sep 4, 2025 at 16:43
Affected Product
Vendor
pgadmin.org
Product
pgAdmin 4
Affected Versions
pgadmin.org pgAdmin 4 0