CVE-2026-6471 – PostgreSQL

CVSS 7.2 IMPORTANT High with EoP or RCE – Expedited Deployment

“Replication privileges can become a path to arbitrary code execution.”

PostgreSQL patched a missing authorization vulnerability in logical decoding. CVE-2026-6471 allows a non-superuser with REPLICATION privileges to load an arbitrary file accessible to the PostgreSQL operating system account, resulting in arbitrary code execution under that account. The CVSS score is 7.2, which is High severity.

Affected versions are those before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24. These releases contain the fix.

Key Details

Affected Product
Postgresql Postgresql
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
CWE Classification
CWE-862
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.