PT-2026-7633 · Unknown+1 · Postgresql Anonymizer+1
Published
2026-02-11
·
Updated
2026-02-12
·
CVE-2026-2360
CVSS v3.1
8.0
High
| Vector | AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
PostgreSQL Anonymizer versions prior to 3.0.1
Description
The software contains a flaw that could allow a user to obtain superuser privileges. This is achieved by creating a custom operator within the public schema and embedding malicious code within that operator. The malicious code is then executed with superuser privileges during the extension creation process. The risk is elevated in PostgreSQL 14 and instances upgraded from PostgreSQL 14 or earlier. PostgreSQL 15 and later versions mitigate this risk by default, as they revoke creation permissions on the public schema. However, exploitation remains possible if a superuser adds a new schema to their search path and grants create privileges to untrusted users, which is discouraged by PostgreSQL documentation.
Recommendations
Upgrade to PostgreSQL Anonymizer version 3.0.1 or later.
Fix
LPE
Uncontrolled Search Path Element
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Postgresql
Postgresql Anonymizer