Missing Encryption of Sensitive Data in PostgreSQL - CVE-2026-14663
Published: August 15, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose cleartext data and tamper with encrypted data.
The vulnerability exists due to improper encryption in pgcrypto functions when processing OpenSSL-disabled ciphers. A remote attacker can observe faulty ciphertext or supply encrypted input to disclose cleartext data and tamper with encrypted data.
The OpenSSL version and configuration determine which ciphers are disabled, and decryption may succeed even with the wrong key.
Affected software
Debian Linux
postgresql-17 (Debian package)
How to mitigate CVE-2026-14663
postgresql-17 (Debian package) - update to 17.11-0+deb13u1