PT-2026-48418 · Postgresql Global Development Group+1 · Postgresql+1

·

CVE-2026-52758

·

Published

2026-06-10

·

Updated

2026-06-11

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ghidra versions prior to 12.1
Description BSim filter types concatenate user-supplied values directly into SQL queries without escaping or parameterization, leading to a SQL injection. This allows remote attackers to inject arbitrary SQL via the BSim network query protocol to read, modify, or delete data within the PostgreSQL database.
Recommendations Update to version 12.1 or later.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-52758
GHSA-8R4F-65CR-FWXM

Affected Products

Ghidra
Postgresql