← Vulnerability feed

Vulnerability record · CVE-2026-2006 · published 12 February 2026

CVE-2026-2006: Postgresql vulnerability

Postgresql · Postgresql

Missing validation of multibyte character length in PostgreSQL text manipulation allows a database user to issue crafted queries that achieve a buffer overrun. That suffices to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.

8.8 CVSS 3.1 High EPSS 1.1% · top 35.2% CWE-129 · CWE-129CWE-1285 · CWE-1285
8.8CVSS 3.1 base score
1.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
34References
15 Jul 2026Last modified by NVD

Description

Missing validation of multibyte character length in PostgreSQL text manipulation allows a database user to issue crafted queries that achieve a buffer overrun. That suffices to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://www.postgresql.org/support/security/CVE-2026-2006/ Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:19009
https://access.redhat.com/errata/RHSA-2026:19010
https://access.redhat.com/errata/RHSA-2026:3730
https://access.redhat.com/errata/RHSA-2026:3887
https://access.redhat.com/errata/RHSA-2026:3896
https://access.redhat.com/errata/RHSA-2026:4024
https://access.redhat.com/errata/RHSA-2026:4059
https://access.redhat.com/errata/RHSA-2026:4063
https://access.redhat.com/errata/RHSA-2026:4064
https://access.redhat.com/errata/RHSA-2026:4074
https://access.redhat.com/errata/RHSA-2026:4075
https://access.redhat.com/errata/RHSA-2026:4110
https://access.redhat.com/errata/RHSA-2026:4254
https://access.redhat.com/errata/RHSA-2026:4441
https://access.redhat.com/errata/RHSA-2026:4475
https://access.redhat.com/errata/RHSA-2026:4504
https://access.redhat.com/errata/RHSA-2026:4505
https://access.redhat.com/errata/RHSA-2026:4506
https://access.redhat.com/errata/RHSA-2026:4509
https://access.redhat.com/errata/RHSA-2026:4515
https://access.redhat.com/errata/RHSA-2026:4516
https://access.redhat.com/errata/RHSA-2026:4518
https://access.redhat.com/errata/RHSA-2026:4524
https://access.redhat.com/errata/RHSA-2026:4528
https://access.redhat.com/errata/RHSA-2026:4544
https://access.redhat.com/errata/RHSA-2026:4546
https://access.redhat.com/errata/RHSA-2026:4547
https://access.redhat.com/errata/RHSA-2026:4548
https://access.redhat.com/errata/RHSA-2026:4943
https://access.redhat.com/errata/RHSA-2026:8756
https://access.redhat.com/security/cve/CVE-2026-2006
https://bugzilla.redhat.com/show_bug.cgi?id=2439324
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-2006.json

Track CVE-2026-2006 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2013-1902Postgresql vulnerabilityPostgreSQL, 9.2.x before 9.2.4, 9.1.x before 9.1.9, 9.0.x before 9.0.13, 8.4.x before 8.4.17, and 8.3.x before 8.3.23 generates insecure temporary fi…EPSS 2.2%10.0CVE-2013-1903Postgresql permissions and access controls vulnerabilityPostgreSQL, possibly 9.2.x before 9.2.4, 9.1.x before 9.1.9, 9.0.x before 9.0.13, 8.4.x before 8.4.17, and 8.3.x before 8.3.23 incorrectly provides t…EPSS 2.2%10.0CVE-2007-3279Postgresql vulnerabilityPostgreSQL 8.1 and probably later versions, when the PL/pgSQL (plpgsql) language has been created, grants certain plpgsql privileges to the PUBLIC do…EPSS 2.6%10.0CVE-2002-1399Postgresql vulnerabilityUnknown vulnerability in cash_out and possibly other functions in PostgreSQL 7.2.1 and earlier, and possibly later versions before 7.2.3, with unknow…EPSS 1.8%9.8CVE-2015-0244Postgresql sql injection vulnerabilityPostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 does not properly handle errors while …EPSS 4.4%9.8CVE-2015-3166Postgresql memory buffer overflow vulnerabilityThe snprintf implementation in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 does no…EPSS 4.6%9.8CVE-2019-10211Postgresql code injection vulnerabilityPostgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via bundled OpenSSL executing code from unprotected di…EPSS 1.8%9.8CVE-2018-16850Postgresql sql injection vulnerabilitypostgresql before versions 11.1, 10.6 is vulnerable to a to SQL injection in pg_upgrade and pg_dump via CREATE TRIGGER ... REFERENCING. Using a purpo…EPSS 5.1%

Source: NIST National Vulnerability Database (record CVE-2026-2006), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.