Untrusted search path in PostgreSQL - CVE-2026-14673
Published: August 15, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary functions with the privileges of expression index owners.
The vulnerability exists due to improper control of search path in amcheck functions when invoking amcheck with a hostile search path. A remote privileged user can set a hostile search path before calling the amcheck function to execute arbitrary functions with the privileges of expression index owners.
Exploitation requires EXECUTE privilege on the amcheck function and affects expression indexes that depend on the search path.
Affected software
Debian Linux
postgresql-17 (Debian package)
How to mitigate CVE-2026-14673
postgresql-17 (Debian package) - update to 17.11-0+deb13u1