Logo
vulnerabilityCVE-2026-6472
Name
CVE-2026-6472
Source
NVD ( link)Debian ( link)
Description
Missing authorization in PostgreSQL CREATE TYPE allows an object creator to hijack other queries that use search_path to find user-defined types, including extension-defined types. That is to say, the victim will execute arbitrary SQL functions of the attacker's choice. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
postgresql
Exploitable

Vulnerability Ratings#


5.4
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
17.10
Not Affected
buildroot
master
18.4
Not Affected
openwrt
master
18.4-r1
Not Affected
yocto
kirkstone
14.22
Exploitable
yocto
master
17.10
Not Affected
yocto
scarthgap
16.14
Not Affected