Improper access control in PostgreSQL - CVE-2026-14681
Published: August 15, 2026
Vulnerability details
The vulnerability allows a remote user to negotiate a connection with lesser protection than required and weaken message integrity protections.
The vulnerability exists due to improper enforcement of message integrity in PostgreSQL GSSAPI support when establishing an initial direct TLS connection. A remote user can negotiate GSSAPI contrary to pg_hba.conf rules to negotiate a connection with lesser protection than required and weaken message integrity protections.
The issue occurs when TLS settings are more permissive than the GSS settings.
Affected software
Debian Linux
postgresql-17 (Debian package)
How to mitigate CVE-2026-14681
postgresql-17 (Debian package) - update to 17.11-0+deb13u1