CVE-2026-12050
Published Jun 19, 2026SQL injection in pgAdmin 4's named restore point endpoint (POST /browser/server/restore_point/{gid}/{sid}). The user-supplied 'value' field was interpolated directly into the SQL…
- evidence mentions
- 2
- Buzz score
- 16.0