Algorithm Downgrade in Postgresql JDBC Driver - CVE-2026-54291

 

Algorithm Downgrade in Postgresql JDBC Driver - CVE-2026-54291

Published: June 30, 2026


Vulnerability identifier: #VU135919
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-54291
CWE-ID: CWE-757
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass channel-binding protection and enable a man-in-the-middle downgrade of authentication.

The vulnerability exists due to failing open and algorithm downgrade in ScramAuthenticator when processing certificates whose signature algorithm has no tls-server-end-point channel-binding hash. A remote attacker can present a certificate with an unsupported signature algorithm while intercepting the TLS connection to bypass channel-binding protection and enable a man-in-the-middle downgrade of authentication.

Only connections configured with channelBinding=require are affected.


Affected software

Postgresql JDBC Driver
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Crucible Data Center
Crucible Server
Crowd Data Center
Bitbucket Data Center
Confluence Data Center
Jira Software Data Center
Bamboo Data Center
Jira Service Management Data Center
Maximo Application Suite - IoT Component

How to mitigate CVE-2026-54291

Install security update from vendor's website.

Postgresql JDBC Driver - update to 42.7.12
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.4.0 Patch 3
Crucible Data Center - update to 4.9.12
Crucible Server - update to 4.9.12
Crowd Data Center - update to 7.2.2
Maximo Application Suite - IoT Component - addressed in versions 9.0.22, 9.1.13, 9.2.1
Bitbucket Data Center - update to 9.4.8
Confluence Data Center - addressed in versions 9.2.11, 10.2.0
Jira Software Data Center - addressed in versions 9.12.38, 10.3.24, 11.3.9
Bamboo Data Center - addressed in versions 10.2.22, 12.1.10
Jira Service Management Data Center - addressed in versions 10.3.24, 11.3.10

External References

Related Security Bulletins