CVE-2026-12045: Read-only transaction bypass in the pgAdmin 4 AI Assistant allows an attacker who can influence database content that the assistant reads to execute arbitrary SQL with the privileges of the pgAdmin...

Added to the CISA Known Exploited Vulnerabilities catalog on 19 Jun 2026. Vendor: AI/ML. Product: LLM. CVSS score: 9.

Read-only transaction bypass in the pgAdmin 4 AI Assistant allows an attacker who can influence database content that the assistant reads to execute arbitrary SQL with the privileges of the pgAdmin user's database role. The AI Assistant's execute_sql_query tool runs LLM-generated SQL inside a BE...

Required action: Review and patch if applicable to your AI infrastructure.