Type Confusion in PostgreSQL - CVE-2026-14680
Published: August 15, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to type confusion in functions with "internal" argument types when invoking such functions from SQL. A remote user can call functions with that argument type to execute arbitrary code.
Successful exploitation can run code as the operating system user running the database.
Affected software
Debian Linux
postgresql-17 (Debian package)
How to mitigate CVE-2026-14680
postgresql-17 (Debian package) - update to 17.11-0+deb13u1