Incorrect permission assignment for critical resource in PostgreSQL - CVE-2026-6469
Published: August 15, 2026
Vulnerability details
The vulnerability allows a remote user to gain unauthorized control over statistics objects.
The vulnerability exists due to improper ownership assignment in the ALTER TABLE ALTER TYPE command when altering a table column type. A remote privileged user can run ALTER TABLE ALTER TYPE to reassign ownership of dependent statistics objects and gain unauthorized control over statistics objects.
This can allow the table owner to run DROP STATISTICS and ALTER STATISTICS on affected dependent statistics objects, while denying those commands to the prior statistics object owner.
Affected software
Debian Linux
postgresql-17 (Debian package)
How to mitigate CVE-2026-6469
postgresql-17 (Debian package) - update to 17.11-0+deb13u1