Type Confusion in PostgreSQL - CVE-2026-16238
Published: August 15, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to type confusion in pg_restore_attribute_stats() when restoring attribute statistics involving conflated range and multirange values. A remote user can create a crafted object to execute arbitrary code.
Code execution occurs as the operating system user running the database.