Logo
vulnerabilityCVE-2026-14680
Name
CVE-2026-14680
Source
NVD ( link)Debian ( link)
Description
Type confusion with PostgreSQL "internal" data type arguments allows any user to execute arbitrary code as the operating system user running the database, via calls to functions with that argument type. Type "internal" represents a class of mutually-incompatible data structures not intended for access from SQL. The system intended to prevent such function calls, but this prevention had gaps. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
postgresql
Exploitable

Vulnerability Ratings#


8.8
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
17.11
Not Affected
buildroot
master
18.6
Not Affected
openwrt
master
18.6-r1
Not Affected
yocto
kirkstone
14.22
Exploitable
yocto
master
18.4
Exploitable
yocto
scarthgap
16.14
Exploitable