CVE-2024-4215

HIGH

pgAdmin4 < 8.6 - Multi-Factor Authentication Bypass

Title source: llm
STIX 2.1

Description

pgAdmin <= 8.5 is affected by a multi-factor authentication bypass vulnerability. This vulnerability allows an attacker with knowledge of a legitimate account’s username and password may authenticate to the application and perform sensitive actions within the application, such as managing files and executing SQL queries, regardless of the account’s MFA enrollment status.

Scores

CVSS v3 7.4
EPSS 0.0003
EPSS Percentile 8.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-89
Status published
Products (3)
fedoraproject/fedora 40
pgadmin/pgadmin_4 < 8.6
pypi/pgadmin4 0 - 8.6PyPI
Published May 02, 2024
Tracked Since Feb 18, 2026