CVE-2026-17566

CRITICALExploit Available
Source

CVE-2026-17566: pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-supplied SQL query into a Jinja template and passin...

NVD/NISTPublished Jul 31, 2026Modified 1mo agoNVDMaturity: weaponized

CVSS Scores

9.9
Base Score
9.4
CVSS v4
Exploitability3.1
Impact6.0

EPSS Score

EPSS Probability0.49%

Higher than 40% of all CVEs

Active exploitation confirmed

EPSS prediction is low but real-world exploitation has been observed. Prioritize remediation regardless of EPSS score.

Exploit intelligence for CVE-2026-17566

Kaitan ID has tracked 3 public exploits for this vulnerability across exploitdb (1), github_poc (1), nvd_ref (1). First exploit code was seen on .

  • github_pocCVE-2026-175662
  • nvd_refReference: Github
  • exploitdbExploit-DB Search: CVE-2026-17566
View all exploit details

Exploit maturity

WeaponizedActive exploit code is publicly available. This vulnerability has been weaponized and may be actively targeted.

  • Public exploit code is available.
  • No vendor patch available yet.

Exploitation probability (EPSS)

EPSS exploitation probability: 0.5% (increased from 0.4%, +19% change). This vulnerability ranks in the top 60% of all CVEs by exploitation likelihood. Last updated on Aug 30, 2026.

Attack surface

This vulnerability is exploitable over the network. low complexity. low privileges required. no user interaction needed. impact extends beyond the vulnerable component.

Primary source

Original advisory or reference for this vulnerability (via NVD).

https://github.com/pgadmin-org/pgadmin4/commit/1496fabe28c9f825f6bac0f0d000d9d3276322c3