Improper Authorization in PostgreSQL - CVE-2026-6470
Published: August 15, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to improper access control in PostgreSQL DDL commands when assigning a range subtype or referencing a type from an SQL expression. A remote user can create a dependency on the type to cause a denial of service.
The issue affects ALTER and DROP operations on the type.
Affected software
Debian Linux
postgresql-17 (Debian package)
How to mitigate CVE-2026-6470
postgresql-17 (Debian package) - update to 17.11-0+deb13u1