PT-2026-48676 · Dalibo · Postgresql Anonymizer
Published
2026-06-11
·
Updated
2026-06-11
·
CVE-2026-11945
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H |
PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a JSON document and placing malicious code inside a particular key-value pair. If a superuser calls the import database rules() or import roles rules() functions, the malicious code is executed with superuser privileges. The problem is resolved in PostgreSQL Anonymizer 3.1.1 and further versions
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Postgresql Anonymizer