CVE-2025-9636

pgAdmin <= 9.7 is affected by a  Cross-Origin Opener Policy (COOP) vulnerability.This vulnerability allows an attacker to manipulate the OAuth flow,potentially leading to unauthorised account access, account takeover, data breaches, and privilege escalation.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.9 HIGH
NETWORK
HIGH
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:L
PostgreSQLCNA
7.9 HIGH
NETWORK
HIGH
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:L
CISA-ADPADP
---
---