Logo
vulnerabilityCVE-2026-14673
Name
CVE-2026-14673
Source
NVD ( link)Debian ( link)
Description
Untrusted search path in PostgreSQL amcheck allows a grantee of amcheck function EXECUTE privilege to execute arbitrary functions as the owners of expression indexes that depend on the search path, via setting a hostile search path before calling the amcheck function. Within major versions 18, 16, 15, and 14, minor versions before PostgreSQL 18.5, 16.15, 15.19, and 14.24 are affected. PostgreSQL 17 is unaffected.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
postgresql
Exploitable

Vulnerability Ratings#


3.8
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
17.11
Not Affected
buildroot
master
18.6
Not Affected
openwrt
master
18.6-r1
Not Affected
openwrt
openwrt-25.12
17.5-r3
Not Affected
yocto
kirkstone
14.22
Exploitable
yocto
scarthgap
16.14
Exploitable