PT-2026-48676 · Dalibo · Postgresql Anonymizer

Published

2026-06-11

·

Updated

2026-06-11

·

CVE-2026-11945

CVSS v3.1

6.4

Medium

VectorAV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H
PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a JSON document and placing malicious code inside a particular key-value pair. If a superuser calls the import database rules() or import roles rules() functions, the malicious code is executed with superuser privileges. The problem is resolved in PostgreSQL Anonymizer 3.1.1 and further versions

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-11945

Affected Products

Postgresql Anonymizer