securityaffairs.com 9/4/2026, 2:30:19 PM · external

PostgreSQL Hit by 12-Year-Old Vulnerability Allowing Server Takeover

PostgreSQL Hit by 12-Year-Old Vulnerability Allowing Server Takeover
CyberSIXT Evidence Panel
CVE Intel
CISA KEV Not in KEV
Patch Patch Available

A severe vulnerability in PostgreSQL, named PostGREShell (CVE-2026-6471), has been identified by Cyera researchers. This flaw, existing in PostgreSQL versions since 2014, allows low-privileged attackers with replication access to execute arbitrary code and achieve superuser privileges. The vulnerability stems from a lack of proper authorization checks in PostgreSQL's logical decoding system, permitting attackers to load malicious files via a chosen plugin.

PostgreSQL has released fixes in versions 18.6, 17.11, 16.15, 15.19, and 14.24. Organizations are urged to update their systems and review replication account privileges to mitigate risks.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline