Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-14673

Опубликовано: 13 авг. 2026
Источник: redhat
CVSS3: 3.8
EPSS Низкий

Описание

Untrusted search path in PostgreSQL amcheck allows a grantee of amcheck function EXECUTE privilege to execute arbitrary functions as the owners of expression indexes that depend on the search path, via setting a hostile search path before calling the amcheck function. Within major versions 18, 16, 15, and 14, minor versions before PostgreSQL 18.5, 16.15, 15.19, and 14.24 are affected. PostgreSQL 17 is unaffected.

An untrusted search path vulnerability in PostgreSQL's amcheck module allows a user with EXECUTE privileges to escalate privileges or execute arbitrary code. By setting a malicious search path before invoking an amcheck function, an attacker can hijack execution to run arbitrary SQL functions with the elevated permissions of the expression index owner.

Отчет

This vulnerability is rated as Low impact because exploitation requires an attacker to already possess EXECUTE privileges on amcheck functions. The necessity of having this pre-existing, elevated database access to manipulate the search path significantly limits the likelihood of successful privilege escalation.

Меры по смягчению последствий

Do not GRANT EXECUTE on amcheck functions (bt_index_check, bt_index_parent_check, verify_heapam, and related) to non-superuser roles. If index verification is unused, drop the extension (DROP EXTENSION amcheck). Restrict PostgreSQL to trusted clients.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10postgresql16Fix deferred
Red Hat Enterprise Linux 10postgresql18Fix deferred
Red Hat Enterprise Linux 6postgresqlNot affected
Red Hat Enterprise Linux 7postgresqlNot affected
Red Hat Enterprise Linux 8postgresql:12/postgresqlFix deferred
Red Hat Enterprise Linux 8postgresql:15/postgresqlFix deferred
Red Hat Enterprise Linux 8postgresql:16/postgresqlFix deferred
Red Hat Enterprise Linux 9postgresqlFix deferred
Red Hat Enterprise Linux 9postgresql:15/postgresqlFix deferred
Red Hat Enterprise Linux 9postgresql:16/postgresqlFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-426
https://bugzilla.redhat.com/show_bug.cgi?id=2515305postgresql: PostgreSQL amcheck: Privilege escalation via untrusted search path

EPSS

Процентиль: 7%
0.00174
Низкий

3.8 Low

CVSS3

Связанные уязвимости

CVSS3: 3.8
ubuntu
около 1 месяца назад

Untrusted search path in PostgreSQL amcheck allows a grantee of amcheck function EXECUTE privilege to execute arbitrary functions as the owners of expression indexes that depend on the search path, via setting a hostile search path before calling the amcheck function. Within major versions 18, 16, 15, and 14, minor versions before PostgreSQL 18.6, 16.15, 15.19, and 14.24 are affected. PostgreSQL 17 is unaffected.

CVSS3: 3.8
nvd
около 1 месяца назад

Untrusted search path in PostgreSQL amcheck allows a grantee of amcheck function EXECUTE privilege to execute arbitrary functions as the owners of expression indexes that depend on the search path, via setting a hostile search path before calling the amcheck function. Within major versions 18, 16, 15, and 14, minor versions before PostgreSQL 18.6, 16.15, 15.19, and 14.24 are affected. PostgreSQL 17 is unaffected.

CVSS3: 3.8
msrc
около 1 месяца назад

PostgreSQL amcheck does not clear untrusted search path

CVSS3: 3.8
debian
около 1 месяца назад

Untrusted search path in PostgreSQL amcheck allows a grantee of amchec ...

CVSS3: 3.8
github
около 1 месяца назад

Untrusted search path in PostgreSQL amcheck allows a grantee of amcheck function EXECUTE privilege to execute arbitrary functions as the owners of expression indexes that depend on the search path, via setting a hostile search path before calling the amcheck function. Within major versions 18, 16, 15, and 14, minor versions before PostgreSQL 18.5, 16.15, 15.19, and 14.24 are affected. PostgreSQL 17 is unaffected.

EPSS

Процентиль: 7%
0.00174
Низкий

3.8 Low

CVSS3