CVE-2026-7815 is a SQL injection vulnerability in the pgAdmin 4 Maintenance Tool affecting pgAdmin 4 versions 7.6 through before 9.15. The flaw arises because four user-controlled JSON fields used by maintenance operations were concatenated directly into generated VACUUM, ANALYZE, and REINDEX SQL statements and then executed via psql using the --command option. This unsafe command construction allowed an authenticated user with the tools_maintenance permission to break out of the intended option syntax and inject arbitrary SQL against the connected PostgreSQL server. The issue also involved improper handling of the tablespace parameter for REINDEX, which was corrected by replacing manual quoting with the qtIdent filter, alongside server-side allow-list validation for all affected fields.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A SQL injection vulnerability in pgAdmin 4 Maintenance Tool that allows an authenticated user with tools_maintenance permission to execute arbitrary SQL on the connected PostgreSQL server and potentially escalate to OS command execution on the database host.
A SQL injection vulnerability in pgAdmin 4's Maintenance Tool that can allow an authenticated user to escalate from SQL injection to operating system command execution on the database host, including via PostgreSQL COPY ... TO PROGRAM when connected with superuser privileges.
A SQL injection vulnerability in pgAdmin 4 affecting Maintenance tool option values.
A high-severity SQL injection vulnerability in pgAdmin 4's Maintenance Tool that allows an authenticated user with tools_maintenance permission to inject arbitrary SQL into maintenance commands, potentially escalating to remote code execution on the database host via PostgreSQL COPY ... TO PROGRAM.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.