pgAdmin LDAP Authentication TLS Certificate Verification Bypass Vulnerability

Vulnerability

A vulnerability exists in pgAdmin versions through 9.9 within the LDAP authentication process, allowing attackers to bypass TLS certificate validation. This flaw enables the acceptance of self-signed or invalid server certificates, potentially leading to a man-in-the-middle attack where LDAP credentials can be intercepted and directory responses manipulated. The issue arises because the LDAP TLS client does not validate server certificates unless a certificate authority, client certificate, and client key are all configured. In environments like Active Directory, where mutual TLS validation is typically disabled, this vulnerability can be exploited.

Impact

Exploitation allows on-path attackers to intercept TLS connections using a fraudulent certificate, proxying traffic to steal LDAP bind credentials and alter directory responses.

Remediation

Users can update to pgAdmin version 9.10, where this vulnerability has been addressed.

Added: Nov 13, 2025, 1:20 PM
Updated: Nov 13, 2025, 2:22 PM

Vulnerability Rating

Custom Algorithm
spread
6.8
impact
3.1
exploitability
7.2
remediation
0.0
relevance
1.1
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.