pgAdmin 4 v9.16 has been released with 64 bug fixes and new features, most notably patching seven security vulnerabilities (CVE-2026-12044 through CVE-2026-12050). Critical fixes include SQL injection in dialog templates and a named restore point endpoint, an AI Assistant read-only transaction bypass enabling RCE via COPY TO PROGRAM, unauthenticated SQL Editor endpoints with a pickle deserialization sink, stored XSS allowing credential exfiltration, HTML injection in cloud deployment modules, and an open redirect in the MFA flow. New features include server-color-coded panel headers, middle-click tab closing, configurable Helm chart security contexts, and TOAST tuple target support in Materialized View dialogs. pgAgent has been deprecated and will be removed within six months.

3m read timeFrom postgresql.org
Post cover image
Table of contents
FeaturesSecurity FixesBugs/HousekeepingDeprecations
100.8K Impressions2 Comments