Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-6472

Опубликовано: 14 мая 2026
Источник: redhat
CVSS3: 5.4

Описание

Missing authorization in PostgreSQL CREATE TYPE allows an object creator to hijack other queries that use search_path to find user-defined types, including extension-defined types. That is to say, the victim will execute arbitrary SQL functions of the attacker's choice. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

A flaw was found in PostgreSQL CREATE TYPE handling for multirange types. The database failed to properly verify schema CREATE privileges during multirange type creation. An authenticated database user could exploit this issue to hijack queries that rely on search_path resolution for user-defined or extension-defined types, potentially causing execution of arbitrary SQL functions within the affected database context.

Отчет

This vulnerability affects PostgreSQL multirange type creation functionality. Red Hat Product Security has assessed this issue as a Moderate severity vulnerability. The vulnerability does not directly provide operating system command execution or PostgreSQL superuser privileges. The impact is limited to the affected database context and depends on application query behavior and schema resolution patterns. Therefore, Red Hat assessed the Confidentiality and Integrity impacts as Low (C:L/I:L), with no demonstrated Availability impact (A:N).

Меры по смягчению последствий

Red Hat is not aware of a practical temporary workaround that fully mitigates this issue or meets Red Hat Product Security's standards for usability, deployment, applicability, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6postgresqlOut of support scope
Red Hat Enterprise Linux 7postgresqlFix deferred
Red Hat Enterprise Linux 8postgresqlFix deferred
Red Hat Enterprise Linux 9postgresqlFix deferred
Self-service automation portal 2ansible-automation-platform/bootc-automation-portal-rhel9Fix deferred
Red Hat Enterprise Linux 10postgresql18FixedRHSA-2026:2774222.06.2026
Red Hat Enterprise Linux 10postgresql16FixedRHSA-2026:2774322.06.2026
Red Hat Enterprise Linux 10.0 Extended Update Supportpostgresql16FixedRHSA-2026:2771822.06.2026
Red Hat Enterprise Linux 8postgresqlFixedRHSA-2026:2618116.06.2026
Red Hat Enterprise Linux 8postgresqlFixedRHSA-2026:2814323.06.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-862
https://bugzilla.redhat.com/show_bug.cgi?id=2477436postgresql: PostgreSQL CREATE TYPE does not check multirange schema CREATE privilege

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
ubuntu
3 месяца назад

Missing authorization in PostgreSQL CREATE TYPE allows an object creator to hijack other queries that use search_path to find user-defined types, including extension-defined types. That is to say, the victim will execute arbitrary SQL functions of the attacker's choice. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 5.4
nvd
3 месяца назад

Missing authorization in PostgreSQL CREATE TYPE allows an object creator to hijack other queries that use search_path to find user-defined types, including extension-defined types. That is to say, the victim will execute arbitrary SQL functions of the attacker's choice. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 5.4
msrc
3 месяца назад

PostgreSQL CREATE TYPE does not check multirange schema CREATE privilege

CVSS3: 5.4
debian
3 месяца назад

Missing authorization in PostgreSQL CREATE TYPE allows an object creat ...

CVSS3: 5.4
github
3 месяца назад

Missing authorization in PostgreSQL CREATE TYPE allows an object creator to hijack other queries that use search_path to find user-defined types, including extension-defined types. That is to say, the victim will execute arbitrary SQL functions of the attacker's choice. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

5.4 Medium

CVSS3