Decade-Old PostgreSQL Vulnerability Allows Database Takeover

Decade-Old PostgreSQL Vulnerability Allows Database Takeover

First seen 4 Sep 2026, 12:28 UTC CsoonlineFeeds.Feedburnerwww.postgresql.orgnvd.nist.gov 60.6

Article Content

Browse articles
ThreatCluster

A critical vulnerability in PostgreSQL, tracked as CVE-2026-6471, has been identified, allowing attackers with low-privilege accounts to take over databases and servers. Dubbed PostGREShell, this flaw exists in the database's replication functionality, enabling remote code execution and privilege escalation. The vulnerability affects PostgreSQL versions dating back to 9.4, released in 2014, and was patched in versions 18.6, 17.11, 16.15, 15.19, and 14.24 on August 13, 2026. Attackers can exploit this flaw by loading arbitrary code through a specially crafted logical decoding plugin, which bypasses existing security checks. This could lead to full superuser access, allowing attackers to manipulate database internals and deploy backdoors. The vulnerability has been confirmed to affect installations across Windows, Linux, and macOS, with particular risk noted for Windows systems. Organizations using PostgreSQL are urged to update their systems immediately to mitigate this risk.

Key Points: • CVE-2026-6471 allows low-privilege accounts to execute arbitrary code. • The vulnerability affects PostgreSQL versions since 9.4, patched on August 13, 2026. • Attackers can escalate privileges to superuser, compromising entire databases.

Ask AI about this cluster

Timeline

2026-08-13
CVE-2026-6471 published
PostgreSQL released patches for versions 18.6, 17.11, 16.15, 15.19, and 14.24 to address the vulnerability.
www.postgresql.org
2026-09-03
Vulnerability disclosed by Cyera
Cyera Research revealed a decade-old flaw in PostgreSQL that allows low-privilege accounts to escalate privileges.
Csoonline
2026-09-04
Security advisory published
PostgreSQL confirmed the vulnerability and advised users to update their installations immediately.
Feeds.Feedburner