V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2026-2004
ANC
High

Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object creator to execute arb…

CVSS
8.8
High
EPSS
0.00
p38
Published
2026-01-01
Updated
2026-01-01
Description

Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object creator to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.

Tags · CWE
CWE-1287
Affected products
Postgresql 14.0–14.21Postgresql 15.0–15.16Postgresql 16.0–16.12Postgresql 17.0–17.8Postgresql 18.0–18.2
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Timeline
2026-01-01
Published
2026-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: L
Low (L)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.005 · p38
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
Tracked
postgresql-13Tracked
postgresql-15Tracked
postgresql-17Tracked
postgresql-18Tracked
postgresql*Tracked
Source databases
ANC
DEB
CVE
Related vulnerabilities