ThreatCluster

Critical PostgreSQL Vulnerability Allows Remote Code Execution

First seen 24 Aug 2026, 17:18 UTC Ccb.Belgium.Bewww.postgresql.orgnvd.nist.gov 72

Article Content

Browse articles
ThreatCluster

A heap-based buffer overflow vulnerability, CVE-2026-14669, has been discovered in PostgreSQL's to_char() function, affecting versions prior to 18.5, 17.11, 16.15, 15.19, and 14.24. This vulnerability allows authenticated attackers to execute arbitrary code as the operating system user running the database by supplying an oversized POSIX timezone abbreviation. The vulnerability was published on August 13, 2026, with a proof-of-concept released on August 18, increasing the urgency for organizations to patch their systems. PostgreSQL has released fixes for all supported affected branches. The Centre for Cybersecurity Belgium recommends immediate patching and enhanced monitoring to detect potential intrusions. Organizations are advised to report any incidents promptly. Historical compromises may still exist even after patching.

Key Points: • CVE-2026-14669 allows remote code execution in PostgreSQL due to a buffer overflow. • Affected versions include PostgreSQL 18.4 and earlier; patches were released on August 13, 2026. • Immediate patching is recommended to prevent exploitation, especially after a PoC was made public.

Timeline

2026-08-13
CVE-2026-14669 published
PostgreSQL disclosed a heap-based buffer overflow vulnerability affecting multiple versions.
Ccb.Belgium.Be
2026-08-18
First public PoC released
A proof-of-concept demonstrating the exploitation of the vulnerability was made publicly available.
Ccb.Belgium.Be
2026-08-24
Urgent patching recommended
The Centre for Cybersecurity Belgium urges organizations to patch affected PostgreSQL versions immediately.
Ccb.Belgium.Be