Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reassigns ownership of dependent statistics objects to the current user. This wrongly allows the table owner to run DROP STATISTICS and ALTER STATISTICS via this improper ownership. It wrongly denies those commands to the prior statistics object owner. DROP TABLE remains able to remove statistics objects, so this exploit achieves nothing in many ownership arrangements. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.
CVSS Details
- CVSS 3.1 Base Score: 3.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade postgresql18Upgrade postgresql16Upgrade postgresql15Upgrade postgresql17 | Aug 17, 2026 | Aug 13, 2026 |
| Debian | — | Upgrade postgresql-15Upgrade postgresql-17 | Aug 16, 2026 | Aug 16, 2026 |
| Freebsd | — | Upgrade postgresql18-serverUpgrade postgresql17-serverUpgrade postgresql16-serverUpgrade postgresql14-serverUpgrade postgresql15-server | Aug 17, 2026 | Aug 16, 2026 |
| Postgres | — | Upgrade to PostgreSQL version 16.15Upgrade to PostgreSQL version 14.24Upgrade to PostgreSQL version 17.11Upgrade to PostgreSQL version 15.19Upgrade to PostgreSQL version 18.5 | Aug 14, 2026 | Aug 13, 2026 |
| Ubuntu | — | Upgrade postgresql-14Upgrade postgresql-18Upgrade postgresql-16 | Aug 20, 2026 | Aug 13, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub