A severe vulnerability in PostgreSQL, named PostGREShell (CVE-2026-6471), has been identified by Cyera researchers. This flaw, existing in PostgreSQL versions since 2014, allows low-privileged attackers with replication access to execute arbitrary code and achieve superuser privileges. The vulnerability stems from a lack of proper authorization checks in PostgreSQL's logical decoding system, permitting attackers to load malicious files via a chosen plugin.
PostgreSQL has released fixes in versions 18.6, 17.11, 16.15, 15.19, and 14.24. Organizations are urged to update their systems and review replication account privileges to mitigate risks.