Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-6469

Опубликовано: 13 авг. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 3.8

Описание

Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reassigns ownership of dependent statistics objects to the current user. This wrongly allows the table owner to run DROP STATISTICS and ALTER STATISTICS via this improper ownership. It wrongly denies those commands to the prior statistics object owner. DROP TABLE remains able to remove statistics objects, so this exploit achieves nothing in many ownership arrangements. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.

РелизСтатусПримечание
devel

DNE

esm-infra/bionic

needs-triage

jammy

DNE

noble

DNE

resolute

DNE

upstream

ignored

end of life

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra/focal

needs-triage

jammy

DNE

noble

DNE

resolute

DNE

upstream

ignored

end of life

Показывать по

РелизСтатусПримечание
devel

DNE

jammy

released

14.24-0ubuntu0.22.04.1
noble

DNE

resolute

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

jammy

DNE

noble

released

16.15-0ubuntu0.24.04.1
resolute

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

pending

18.6-3
jammy

DNE

noble

DNE

resolute

released

18.6-0ubuntu0.26.04.1
upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra-legacy/trusty

deferred

2019-08-23
jammy

DNE

noble

DNE

resolute

DNE

upstream

ignored

end of life

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra-legacy/xenial

needs-triage

jammy

DNE

noble

DNE

resolute

DNE

upstream

ignored

end of life

Показывать по

EPSS

Процентиль: 8%
0.00188
Низкий

3.8 Low

CVSS3

Связанные уязвимости

CVSS3: 3.8
nvd
19 дней назад

Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reassigns ownership of dependent statistics objects to the current user. This wrongly allows the table owner to run DROP STATISTICS and ALTER STATISTICS via this improper ownership. It wrongly denies those commands to the prior statistics object owner. DROP TABLE remains able to remove statistics objects, so this exploit achieves nothing in many ownership arrangements. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

CVSS3: 3.8
msrc
18 дней назад

PostgreSQL ALTER TABLE ALTER TYPE resets extended statistics ownership

CVSS3: 3.8
debian
19 дней назад

Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE co ...

CVSS3: 3.8
github
19 дней назад

Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reassigns ownership of dependent statistics objects to the current user. This wrongly allows the table owner to run DROP STATISTICS and ALTER STATISTICS via this improper ownership. It wrongly denies those commands to the prior statistics object owner. DROP TABLE remains able to remove statistics objects, so this exploit achieves nothing in many ownership arrangements. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.

CVSS3: 3.8
fstec
20 дней назад

Уязвимость команды ALTER TABLE ALTER TYPE системы управления базами данных PostgreSQL, позволяющая нарушителю получить несанкционированный доступ на удаление или изменение данных

EPSS

Процентиль: 8%
0.00188
Низкий

3.8 Low

CVSS3

Уязвимость CVE-2026-6469