Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-14680

Опубликовано: 13 авг. 2026
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

Type confusion with PostgreSQL "internal" data type arguments allows any user to execute arbitrary code as the operating system user running the database, via calls to functions with that argument type. Type "internal" represents a class of mutually-incompatible data structures not intended for access from SQL. The system intended to prevent such function calls, but this prevention had gaps. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.

A type confusion vulnerability in PostgreSQL allows any user to execute arbitrary code as the database's operating system user by calling functions with mishandled "internal" data type arguments.

Отчет

This is an Important vulnerability where any authenticated PostgreSQL user can achieve arbitrary code execution as the operating system user running the database. This type confusion flaw bypasses intended security boundaries for 'internal' data types, leading to a significant privilege escalation and potential compromise of the entire database server.

Меры по смягчению последствий

Restrict PostgreSQL to trusted hosts and bind only the required interfaces; use pg_hba.conf so only trusted clients can reach the port. Do not grant CONNECT (or any SQL login) to untrusted roles —any session can trigger this.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10postgresql16Affected
Red Hat Enterprise Linux 10postgresql18Affected
Red Hat Enterprise Linux 6postgresqlOut of support scope
Red Hat Enterprise Linux 7postgresqlAffected
Red Hat Enterprise Linux 8postgresql:12/postgresqlAffected
Red Hat Enterprise Linux 8postgresql:15/postgresqlAffected
Red Hat Enterprise Linux 8postgresql:16/postgresqlAffected
Red Hat Enterprise Linux 9postgresqlAffected
Red Hat Enterprise Linux 9postgresql:15/postgresqlAffected
Red Hat Enterprise Linux 9postgresql:16/postgresqlAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-843
https://bugzilla.redhat.com/show_bug.cgi?id=2515308postgresql: PostgreSQL: Arbitrary code execution via type confusion with "internal" arguments

EPSS

Процентиль: 36%
0.00423
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 1 месяца назад

Type confusion with PostgreSQL "internal" data type arguments allows any user to execute arbitrary code as the operating system user running the database, via calls to functions with that argument type. Type "internal" represents a class of mutually-incompatible data structures not intended for access from SQL. The system intended to prevent such function calls, but this prevention had gaps. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

CVSS3: 8.8
nvd
около 1 месяца назад

Type confusion with PostgreSQL "internal" data type arguments allows any user to execute arbitrary code as the operating system user running the database, via calls to functions with that argument type. Type "internal" represents a class of mutually-incompatible data structures not intended for access from SQL. The system intended to prevent such function calls, but this prevention had gaps. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

msrc
около 1 месяца назад

PostgreSQL type confusion via "internal" arguments

CVSS3: 8.8
debian
около 1 месяца назад

Type confusion with PostgreSQL "internal" data type arguments allows a ...

CVSS3: 8.8
github
около 1 месяца назад

Type confusion with PostgreSQL "internal" data type arguments allows any user to execute arbitrary code as the operating system user running the database, via calls to functions with that argument type. Type "internal" represents a class of mutually-incompatible data structures not intended for access from SQL. The system intended to prevent such function calls, but this prevention had gaps. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.

EPSS

Процентиль: 36%
0.00423
Низкий

8.8 High

CVSS3