Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating system account running the server, via the choice of logical decoding plugin. This in turn runs arbitrary code as that account. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.
CVSS Details
- CVSS 3.1 Base Score: 7.2
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade postgresql15Upgrade postgresql16Upgrade postgresql18Upgrade postgresql17 | Aug 17, 2026 | Aug 13, 2026 |
| Debian | — | Upgrade postgresql-15Upgrade postgresql-17 | Aug 16, 2026 | Aug 16, 2026 |
| Freebsd | — | Upgrade postgresql18-serverUpgrade postgresql17-serverUpgrade postgresql16-serverUpgrade postgresql15-serverUpgrade postgresql14-server | Aug 17, 2026 | Aug 16, 2026 |
| Postgres | — | Upgrade to PostgreSQL version 16.15Upgrade to PostgreSQL version 17.11Upgrade to PostgreSQL version 18.5Upgrade to PostgreSQL version 14.24Upgrade to PostgreSQL version 15.19 | Aug 14, 2026 | Aug 13, 2026 |
| Ubuntu | — | Upgrade postgresql-16Upgrade postgresql-14Upgrade postgresql-18 | Aug 20, 2026 | Aug 13, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub