All CVEs
Vulnerability intelligence

CVE-2024-0985

CWE-271

Late privilege drop in REFRESH MATERIALIZED VIEW CONCURRENTLY in PostgreSQL allows an object creator to execute arbitrary SQL functions as the command issuer. The command intends to run SQL functions as the owner of the materialized view, enabling safe refresh of untrusted materialized views. The victim is a superuser or member of one of the attacker's roles. The attack requires luring the victim into running REFRESH MATERIALIZED VIEW CONCURRENTLY on the attacker's materialized view. Versions before PostgreSQL 16.2, 15.6, 14.11, 13.14, and 12.18 are affected.

CVSS Score
8
High
EPSS — Exploit Probability
1.5%
Riskier than 71% of all CVEs
Exploitation
Not in CISA KEV
No federal exploitation record
Remediation
unknown
Vendor fix published
NVD entry Vendor patch PoC / advisory

1 article across 1 outlet · first covered Apr 30, 2026 · latest Apr 30, 2026

Coverage timeline