CVE Tools

12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover

SecurityWeekBy Ionut Arghire

PatchPostgreSQL

Our summary

Cyera researchers disclosed a high-severity flaw, tracked as CVE-2026-6471 (CVSS 7.2) and dubbed "PostGREShell," affecting all PostgreSQL releases from 2014 onward. This unauthorized access issue exists within the logical decoding mechanism, allowing an attacker holding specific Replication privileges to execute arbitrary code on the server operating system. By exploiting the defect, threat actors can escalate permissions to full superuser status, extract sensitive data, and establish persistent backdoors. The PostgreSQL Global Development Group has resolved the vulnerability in recent point releases, specifically versions 18.6, 17.11, 16.15, 15.19, and 14.24.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store