CVE-2026-6471 – PostgreSQL
CVSS 7.2
IMPORTANT
High with EoP or RCE – Expedited Deployment
“Replication privileges can become a path to arbitrary code execution.”
PostgreSQL patched a missing authorization vulnerability in logical decoding. CVE-2026-6471 allows a non-superuser with REPLICATION privileges to load an arbitrary file accessible to the PostgreSQL operating system account, resulting in arbitrary code execution under that account. The CVSS score is 7.2, which is High severity.
Affected versions are those before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24. These releases contain the fix.
Key Details
- Affected Product
- Postgresql Postgresql
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- High
- User Interaction
- None
- CWE Classification
- CWE-862
Patch this CVE on all your endpoints in under 5 minutes.
First 200 endpoints are free forever, scale as needed.