Security Digest: June 19, 2026 - 6 Critical Vulnerabilities
Six critical vulnerabilities disclosed today can lead to remote code execution, stored XSS, SQL injection, and unauthorized agent execution. The most urgent exposure is in pgAdmin 4, where multiple flaws affect web-facing admin workflows and could enable code execution or attacker-controlled database actions.
· 8 min read
Today's Critical Security Alert: Patch pgAdmin, AVer Cameras, and PraisonAI Immediately
Executive Summary
Six critical vulnerabilities disclosed today can lead to remote code execution, stored XSS, SQL injection, and unauthorized agent execution. The most urgent exposure is in pgAdmin 4, where multiple flaws affect web-facing admin workflows and could enable code execution or attacker-controlled database actions. If you run any of the affected products, prioritize patching now and restrict access until updates are in place.
Security teams should treat the pgAdmin issues as a cluster: one product, multiple attack paths, and several ways for a low-privilege attacker or malicious database content to escalate impact. Separately, AVer camera users should assume unauthenticated remote takeover risk, and PraisonAI deployments should immediately lock down the AGUI endpoint.
Critical Vulnerabilities
CVE-2026-40624: AVer camera remote code execution via crafted web request
- Impact: A remote, unauthenticated attacker can execute arbitrary code on affected cameras.
- Affected Systems: AVer PTC500S, PTC115, PTC500+, and PTC115+ cameras.
- Immediate Action: Disconnect exposed devices from the internet, restrict management access to trusted networks, and apply vendor firmware updates as soon as available.
- Mitigation: Patch immediately; if patching is delayed, place the devices behind VPN or firewall rules and disable public web access.
CVE-2026-12048: pgAdmin 4 stored XSS in error and plan rendering
- Impact: An attacker-controlled PostgreSQL server, or attacker-influenced object names, can inject HTML/JavaScript into pgAdmin and hijack the browser session.
- Affected Systems: pgAdmin 4 from 6.0 before 9.16.
- Immediate Action: Upgrade pgAdmin 4 to 9.16 or later immediately; avoid connecting to untrusted PostgreSQL servers until patched.
- Mitigation: Deploy the vendor fix, then review any recent connections to untrusted databases and reset browser sessions if suspicious activity is detected.
CVE-2026-12045: pgAdmin 4 AI Assistant read-only transaction bypass
- Impact: An attacker can use prompt injection to make the AI Assistant run arbitrary SQL with the pgAdmin user’s database privileges; in high-privilege cases, this can extend to host-level code execution.
- Affected Systems: pgAdmin 4 from 9.13 before 9.16.
- Immediate Action: Disable or restrict the AI Assistant feature until patched, and upgrade to 9.16 or later.
- Mitigation: Patch now; also review database roles used by pgAdmin and remove unnecessary high-risk privileges such as
pg_execute_server_program.
CVE-2026-12046: pgAdmin 4 unauthenticated SQL Editor endpoint access
- Impact: In server mode, unauthenticated requests can reach sensitive SQL Editor endpoints; with additional session-file compromise, this can become code execution.
- Affected Systems: pgAdmin 4 from 6.9 before 9.16, server mode only.
- Immediate Action: Upgrade to 9.16 or later and restrict server-mode exposure until patched.
- Mitigation: Apply the update, verify that the instance is not publicly reachable, and inspect session storage permissions and secrets management.
CVE-2026-12044: pgAdmin 4 SQL injection in object description dialogs
- Impact: Authenticated users can inject SQL through object description fields; in privileged database roles, this can lead to OS command execution on the PostgreSQL host.
- Affected Systems: pgAdmin 4 from 1.0 before 9.16.
- Immediate Action: Upgrade to 9.16 or later and review any workflows that allow users to edit object descriptions.
- Mitigation: Patch immediately; limit high-privilege PostgreSQL roles and avoid granting
COPY ... TO/FROM PROGRAMwhere possible.
CVE-2026-56076: PraisonAI AGUI cross-origin agent execution
- Impact: Remote attackers can trigger arbitrary agent execution and potentially exfiltrate tool outputs and environment data.
- Affected Systems: PraisonAI before 1.5.128.
- Immediate Action: Upgrade to 1.5.128 or later, and block unauthenticated internet access to
/aguiimmediately. - Mitigation: Patch now; if immediate upgrade is not possible, remove public exposure, enforce authentication at the reverse proxy, and restrict cross-origin access.
What to Do Now
- Patch first: Update pgAdmin 4 to 9.16+, PraisonAI to 1.5.128+, and apply the latest AVer firmware from the vendor.
- Reduce exposure: Remove public access to admin consoles, camera management interfaces, and the PraisonAI AGUI endpoint until updates are confirmed.
- Review privileges: Check PostgreSQL roles used by pgAdmin and remove unnecessary superuser or program-execution permissions.
- Disable risky features: Turn off pgAdmin AI Assistant if you cannot patch immediately.
- Verify deployment state: Confirm version numbers, restart services after patching, and validate that authentication is enforced on all admin routes.
- Monitor for abuse: Look for unexpected browser redirects, suspicious SQL statements, unusual database writes, and agent activity from untrusted origins.
Verification steps: Confirm installed versions against vendor release notes, test that pgAdmin is no longer reachable without login in server mode, and ensure reverse proxies are not exposing PraisonAI’s AGUI endpoint to the public internet.
Monitoring recommendations: Watch web logs for crafted requests to camera management pages, pgAdmin error-rendering or SQL Editor routes, and repeated AGUI POSTs. Alert on new database objects, unexpected transaction control statements, and any outbound connections from admin tooling that should remain internal.
Related Resources
- Internal: A follow-up analysis and hardening checklist will be published on the internal security blog; link to be added when available.
- Official vendor advisories: Refer to the AVer, pgAdmin, and PraisonAI security advisories and release notes for patched versions and deployment guidance.