PT-2026-40921 · Postgresql Global Development Group+3 · Postgresql+2
Yu Kunpeng
·
Published
2026-05-14
·
Updated
2026-05-21
·
CVE-2026-6476
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
PostgreSQL versions 17.0 through 17.9
PostgreSQL versions 18.0 through 18.3
Description
SQL injection in the
pg createsubscriber function allows an attacker with pg create subscription rights to execute arbitrary SQL commands with superuser privileges. The attack is triggered when pg createsubscriber is subsequently executed.Recommendations
Update PostgreSQL version 17 to 17.10.
Update PostgreSQL version 18 to 18.4.
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linuxmint
Postgresql
Ubuntu