Improper Authorization in PostgreSQL - CVE-2026-6471
Published: August 15, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper access control in logical decoding when selecting a logical decoding plugin. A remote privileged user can choose an arbitrary file visible to the server operating system account as a logical decoding plugin to execute arbitrary code.
Exploitation requires the REPLICATION privilege but does not require superuser privileges.
Affected software
Debian Linux
postgresql-17 (Debian package)
How to mitigate CVE-2026-6471
postgresql-17 (Debian package) - update to 17.11-0+deb13u1