Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-15741

Опубликовано: 13 авг. 2026
Источник: redhat
CVSS3: 8

Описание

SQL injection in PostgreSQL EXTRACT() deparse allows an object owner to execute arbitrary SQL as a superuser via a hostile object definition. Attacks affect expression deparse consumers broadly, including pg_dump, psql commands like \sf, and any similar usage in non-core tools. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.

A SQL injection flaw in PostgreSQL's EXTRACT() expression deparser allows an authenticated object owner to execute arbitrary SQL commands with superuser privileges. By defining a hostile database object, an attacker can achieve privilege escalation when deparsing tools like pg_dump or psql inspect or export the object.

Отчет

An Important-rated SQL injection vulnerability in PostgreSQL's EXTRACT() expression deparser allows an authenticated object owner to execute arbitrary SQL commands with superuser privileges. By crafting a hostile database object, an attacker can trigger privilege escalation when administrative tools like pg_dump or psql process the object. This poses a significant risk to environments where non-administrative users are granted object creation rights.

Меры по смягчению последствий

To mitigate this vulnerability, administrators should strictly limit database object creation privileges to highly trusted users. When performing backups or database introspection using pg_dump or psql, exercise caution when operating on databases that allow untrusted users to define objects,

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10postgresql16Affected
Red Hat Enterprise Linux 10postgresql18Affected
Red Hat Enterprise Linux 6postgresqlOut of support scope
Red Hat Enterprise Linux 7postgresqlAffected
Red Hat Enterprise Linux 8postgresql:12/postgresqlAffected
Red Hat Enterprise Linux 8postgresql:15/postgresqlAffected
Red Hat Enterprise Linux 8postgresql:16/postgresqlAffected
Red Hat Enterprise Linux 9postgresqlAffected
Red Hat Enterprise Linux 9postgresql:15/postgresqlAffected
Red Hat Enterprise Linux 9postgresql:16/postgresqlAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-89
https://bugzilla.redhat.com/show_bug.cgi?id=2515332postgresql: PostgreSQL: Privilege escalation via SQL injection in EXTRACT() deparse

8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 1 месяца назад

SQL injection in PostgreSQL EXTRACT() deparse allows an object owner to execute arbitrary SQL as a superuser via a hostile object definition. Attacks affect expression deparse consumers broadly, including pg_dump, psql commands like \sf, and any similar usage in non-core tools. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

CVSS3: 8.8
nvd
около 1 месяца назад

SQL injection in PostgreSQL EXTRACT() deparse allows an object owner to execute arbitrary SQL as a superuser via a hostile object definition. Attacks affect expression deparse consumers broadly, including pg_dump, psql commands like \sf, and any similar usage in non-core tools. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

CVSS3: 8.8
msrc
около 1 месяца назад

PostgreSQL expression deparse allows SQL injection via EXTRACT argument

CVSS3: 8.8
debian
около 1 месяца назад

SQL injection in PostgreSQL EXTRACT() deparse allows an object owner t ...

CVSS3: 8.8
github
около 1 месяца назад

SQL injection in PostgreSQL EXTRACT() deparse allows an object owner to execute arbitrary SQL as a superuser via a hostile object definition. Attacks affect expression deparse consumers broadly, including pg_dump, psql commands like \sf, and any similar usage in non-core tools. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.

8 High

CVSS3