Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2026-14673

Опубликовано: 14 авг. 2026
Источник: msrc
CVSS3: 3.8
EPSS Низкий

Описание

PostgreSQL amcheck does not clear untrusted search path

EPSS

Процентиль: 7%
0.00174
Низкий

3.8 Low

CVSS3

Связанные уязвимости

CVSS3: 3.8
ubuntu
около 1 месяца назад

Untrusted search path in PostgreSQL amcheck allows a grantee of amcheck function EXECUTE privilege to execute arbitrary functions as the owners of expression indexes that depend on the search path, via setting a hostile search path before calling the amcheck function. Within major versions 18, 16, 15, and 14, minor versions before PostgreSQL 18.5, 16.15, 15.19, and 14.24 are affected. PostgreSQL 17 is unaffected.

CVSS3: 3.8
nvd
около 1 месяца назад

Untrusted search path in PostgreSQL amcheck allows a grantee of amcheck function EXECUTE privilege to execute arbitrary functions as the owners of expression indexes that depend on the search path, via setting a hostile search path before calling the amcheck function. Within major versions 18, 16, 15, and 14, minor versions before PostgreSQL 18.5, 16.15, 15.19, and 14.24 are affected. PostgreSQL 17 is unaffected.

CVSS3: 3.8
debian
около 1 месяца назад

Untrusted search path in PostgreSQL amcheck allows a grantee of amchec ...

CVSS3: 3.8
github
около 1 месяца назад

Untrusted search path in PostgreSQL amcheck allows a grantee of amcheck function EXECUTE privilege to execute arbitrary functions as the owners of expression indexes that depend on the search path, via setting a hostile search path before calling the amcheck function. Within major versions 18, 16, 15, and 14, minor versions before PostgreSQL 18.5, 16.15, 15.19, and 14.24 are affected. PostgreSQL 17 is unaffected.

CVSS3: 3.8
fstec
около 1 месяца назад

Уязвимость расширения amcheck системы управления базами данных PostgreSQL, позволяющая нарушителю повысить свои привилегии и выполнить произвольный код

EPSS

Процентиль: 7%
0.00174
Низкий

3.8 Low

CVSS3