Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2026-11954

Опубликовано: 13 авг. 2026
Источник: fstec
CVSS3: 4.2
CVSS2: 3.6
EPSS Низкий

Описание

Уязвимость системы управления базами данных PostgreSQL связана с неверным сроком действия сеанса. Эксплуатация уязвимости может позволить нарушителю, действующему удаленно, получить несанкционированный доступ на чтение и изменение данных

Вендор

PostgreSQL Global Development Group

Наименование ПО

PostgreSQL

Версия ПО

до 18.5 (PostgreSQL)
до 17.11 (PostgreSQL)
до 16.15 (PostgreSQL)
до 15.19 (PostgreSQL)
до 14.24 (PostgreSQL)

Тип ПО

СУБД

Операционные системы и аппаратные платформы

-

Уровень опасности уязвимости

Низкий уровень опасности (базовая оценка CVSS 2.0 составляет 3,6)
Средний уровень опасности (базовая оценка CVSS 3.1 составляет 4,2)

Возможные меры по устранению уязвимости

Использование рекомендаций производителя:
https://www.postgresql.org/support/security/CVE-2026-14666
Компенсирующие меры:
- перезапуск базы данных или завершение пользовательских сессий сразу после любых изменений ролей, владельца или атрибутов для принудительной инвалидации кеша;
- внедрение мониторинга и аудита использования политик RLS для обнаружения неожиданных паттернов доступа к данным.

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Данные уточняются

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 11%
0.00209
Низкий

4.2 Medium

CVSS3

3.6 Low

CVSS2

Связанные уязвимости

CVSS3: 4.2
ubuntu
11 дней назад

Incomplete tracking in PostgreSQL of changes to role membership, role attributes, and database ownership allows a query to continue using cached row-level security policies after those changes require a different policy, via plan reuse. Stale policies continue until some other event invalidates the cache or connection termination ends the session. This permits a user to complete reads and modifications that were recently permitted but now forbidden. An attacker must tailor an attack to a particular application's pattern of privilege removal and role-specific row security policies. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.

CVSS3: 4.2
nvd
11 дней назад

Incomplete tracking in PostgreSQL of changes to role membership, role attributes, and database ownership allows a query to continue using cached row-level security policies after those changes require a different policy, via plan reuse. Stale policies continue until some other event invalidates the cache or connection termination ends the session. This permits a user to complete reads and modifications that were recently permitted but now forbidden. An attacker must tailor an attack to a particular application's pattern of privilege removal and role-specific row security policies. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.

msrc
9 дней назад

PostgreSQL row security caching disregards role modifications

CVSS3: 4.2
debian
11 дней назад

Incomplete tracking in PostgreSQL of changes to role membership, role ...

CVSS3: 4.2
github
10 дней назад

Incomplete tracking in PostgreSQL of changes to role membership, role attributes, and database ownership allows a query to continue using cached row-level security policies after those changes require a different policy, via plan reuse. Stale policies continue until some other event invalidates the cache or connection termination ends the session. This permits a user to complete reads and modifications that were recently permitted but now forbidden. An attacker must tailor an attack to a particular application's pattern of privilege removal and role-specific row security policies. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.

EPSS

Процентиль: 11%
0.00209
Низкий

4.2 Medium

CVSS3

3.6 Low

CVSS2