CVE-2026-12045: pgAdmin 4 AI Assistant read-only transaction bypass via prompt injection
A vulnerability in the pgAdmin 4 AI Assistant's execute_sql_query tool allowed multi-statement LLM-generated SQL to terminate the read-only transaction wrapper and run arbitrary SQL with the pgAdmin user's database privileges. Delivered via prompt injection through attacker-controlled database content, it enabled unauthorised data modification and, with superuser or pg_execute_server_program roles, remote code execution via COPY ... TO PROGRAM.
Disclosed 18 June 2026 · Record updated 13 September 2026
Impact
Attackers able to write content the AI Assistant reads could execute arbitrary SQL as the pgAdmin user's database role, enabling unauthorised data modification and potential remote code execution on the database server host.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-12045
