Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-6472

Опубликовано: 14 мая 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 5.4

Описание

Missing authorization in PostgreSQL CREATE TYPE allows an object creator to hijack other queries that use search_path to find user-defined types, including extension-defined types. That is to say, the victim will execute arbitrary SQL functions of the attacker's choice. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

РелизСтатусПримечание
devel

DNE

esm-infra/bionic

needs-triage

jammy

DNE

noble

DNE

questing

DNE

resolute

DNE

upstream

ignored

end of life

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra/focal

needs-triage

jammy

DNE

noble

DNE

questing

DNE

resolute

DNE

upstream

ignored

end of life

Показывать по

РелизСтатусПримечание
devel

DNE

jammy

released

14.23-0ubuntu0.22.04.1
noble

DNE

questing

DNE

resolute

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

jammy

DNE

noble

released

16.14-0ubuntu0.24.04.1
questing

DNE

resolute

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

jammy

DNE

noble

DNE

questing

released

17.10-0ubuntu0.25.10.1
resolute

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

pending

18.4-1ubuntu2
jammy

DNE

noble

DNE

questing

DNE

resolute

released

18.4-0ubuntu0.26.04.1
upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra-legacy/trusty

deferred

2019-08-23
jammy

DNE

noble

DNE

questing

DNE

resolute

DNE

upstream

ignored

end of life

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra-legacy/xenial

needs-triage

jammy

DNE

noble

DNE

questing

DNE

resolute

DNE

upstream

ignored

end of life

Показывать по

EPSS

Процентиль: 5%
0.00159
Низкий

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
redhat
3 месяца назад

Missing authorization in PostgreSQL CREATE TYPE allows an object creator to hijack other queries that use search_path to find user-defined types, including extension-defined types. That is to say, the victim will execute arbitrary SQL functions of the attacker's choice. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 5.4
nvd
3 месяца назад

Missing authorization in PostgreSQL CREATE TYPE allows an object creator to hijack other queries that use search_path to find user-defined types, including extension-defined types. That is to say, the victim will execute arbitrary SQL functions of the attacker's choice. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 5.4
msrc
3 месяца назад

PostgreSQL CREATE TYPE does not check multirange schema CREATE privilege

CVSS3: 5.4
debian
3 месяца назад

Missing authorization in PostgreSQL CREATE TYPE allows an object creat ...

CVSS3: 5.4
github
3 месяца назад

Missing authorization in PostgreSQL CREATE TYPE allows an object creator to hijack other queries that use search_path to find user-defined types, including extension-defined types. That is to say, the victim will execute arbitrary SQL functions of the attacker's choice. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

EPSS

Процентиль: 5%
0.00159
Низкий

5.4 Medium

CVSS3