Logo
vulnerabilityCVE-2026-6476
Name
CVE-2026-6476
Source
NVD ( link)Debian ( link)
Description
SQL injection in PostgreSQL pg_createsubscriber allows an attacker with pg_create_subscription rights to execute arbitrary SQL as a superuser. The attack takes effect when pg_createsubscriber next runs. Within major versions 17 and 18, minor versions before PostgreSQL 18.4 and 17.10 are affected. Versions before PostgreSQL 17 are unaffected.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
postgresql
Exploitable

Vulnerability Ratings#


7.2
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
17.10
Not Affected
buildroot
master
18.4
Not Affected
openwrt
master
18.4-r1
Not Affected
yocto
kirkstone
14.22
Not Affected
yocto
master
17.10
Not Affected
yocto
scarthgap
16.14
Not Affected