Security Advisory

CVE-2025-9636

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-09-04 16:43:27
Last updated 2026-02-26 17:49:38
Assigner PostgreSQL
State PUBLISHED

Description

pgAdmin <= 9.7 is affected by a Cross-Origin Opener Policy (COOP) vulnerability. This vulnerability allows an attacker to manipulate the OAuth flow, potentially leading to unauthorised account access, account takeover, data breaches, and privilege escalation.