Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-14666

Опубликовано: 13 авг. 2026
Источник: redhat
CVSS3: 4.2
EPSS Низкий

Описание

Incomplete tracking in PostgreSQL of changes to role membership, role attributes, and database ownership allows a query to continue using cached row-level security policies after those changes require a different policy, via plan reuse. Stale policies continue until some other event invalidates the cache or connection termination ends the session. This permits a user to complete reads and modifications that were recently permitted but now forbidden. An attacker must tailor an attack to a particular application's pattern of privilege removal and role-specific row security policies. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.

A flaw in PostgreSQL allows users to bypass row-level security (RLS) due to incomplete tracking of user role and database ownership changes. Active sessions may continue using cached, outdated security policies, enabling unauthorized read or write access to data. Exploitation requires the attacker to understand the application's specific privilege removal configurations.

Отчет

This vulnerability in PostgreSQL is of Moderate impact. It allows a low-privileged authenticated user to bypass row-level security policies due to stale cached plans, potentially leading to unauthorized data access or modification. Exploitation requires specific timing and an attacker to understand the application's privilege management and row security policy patterns, making it a complex attack.

Меры по смягчению последствий

To mitigate this issue, ensure that all active PostgreSQL sessions are terminated or restarted after any changes to role membership, role attributes, or database ownership that affect row-level security policies. This action forces the invalidation of stale cached security policies, preventing unauthorized data access. Note that terminating sessions will disrupt active user connections.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10postgresql16Fix deferred
Red Hat Enterprise Linux 10postgresql18Fix deferred
Red Hat Enterprise Linux 6postgresqlNot affected
Red Hat Enterprise Linux 7postgresqlNot affected
Red Hat Enterprise Linux 8postgresql:12/postgresqlFix deferred
Red Hat Enterprise Linux 8postgresql:15/postgresqlFix deferred
Red Hat Enterprise Linux 8postgresql:16/postgresqlFix deferred
Red Hat Enterprise Linux 9postgresqlFix deferred
Red Hat Enterprise Linux 9postgresql:15/postgresqlFix deferred
Red Hat Enterprise Linux 9postgresql:16/postgresqlFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-524
https://bugzilla.redhat.com/show_bug.cgi?id=2515309postgresql: PostgreSQL: Row security caching disregards role modifications leading to unauthorized data access

EPSS

Процентиль: 7%
0.00175
Низкий

4.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.2
ubuntu
около 1 месяца назад

Incomplete tracking in PostgreSQL of changes to role membership, role attributes, and database ownership allows a query to continue using cached row-level security policies after those changes require a different policy, via plan reuse. Stale policies continue until some other event invalidates the cache or connection termination ends the session. This permits a user to complete reads and modifications that were recently permitted but now forbidden. An attacker must tailor an attack to a particular application's pattern of privilege removal and role-specific row security policies. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

CVSS3: 4.2
nvd
около 1 месяца назад

Incomplete tracking in PostgreSQL of changes to role membership, role attributes, and database ownership allows a query to continue using cached row-level security policies after those changes require a different policy, via plan reuse. Stale policies continue until some other event invalidates the cache or connection termination ends the session. This permits a user to complete reads and modifications that were recently permitted but now forbidden. An attacker must tailor an attack to a particular application's pattern of privilege removal and role-specific row security policies. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

CVSS3: 4.2
msrc
около 1 месяца назад

PostgreSQL row security caching disregards role modifications

CVSS3: 4.2
debian
около 1 месяца назад

Incomplete tracking in PostgreSQL of changes to role membership, role ...

CVSS3: 4.2
github
около 1 месяца назад

Incomplete tracking in PostgreSQL of changes to role membership, role attributes, and database ownership allows a query to continue using cached row-level security policies after those changes require a different policy, via plan reuse. Stale policies continue until some other event invalidates the cache or connection termination ends the session. This permits a user to complete reads and modifications that were recently permitted but now forbidden. An attacker must tailor an attack to a particular application's pattern of privilege removal and role-specific row security policies. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.

EPSS

Процентиль: 7%
0.00175
Низкий

4.2 Medium

CVSS3