Logo
vulnerabilityCVE-2026-6469
Name
CVE-2026-6469
Source
NVD ( link)Debian ( link)
Description
Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reassigns ownership of dependent statistics objects to the current user. This wrongly allows the table owner to run DROP STATISTICS and ALTER STATISTICS via this improper ownership. It wrongly denies those commands to the prior statistics object owner. DROP TABLE remains able to remove statistics objects, so this exploit achieves nothing in many ownership arrangements. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
postgresql
Exploitable

Vulnerability Ratings#


3.8
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
17.11
Not Affected
buildroot
master
18.6
Not Affected
openwrt
master
18.6-r1
Not Affected
openwrt
openwrt-25.12
17.5-r3
Exploitable
yocto
kirkstone
14.22
Exploitable
yocto
scarthgap
16.14
Exploitable