Story thread · 2 reports / 2 sources
PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution
thehackernews.com · 10d

PostgreSQL has released updates to address a security flaw that allows an account with the REPLICATION attribute to run arbitrary code as the operating-system user running the database server. The flaw, tracked as CVE-2026-6471 (CVSS score: 7.2), has been present since logical decoding was introduced in PostgreSQL 9.4 in 2014. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are
First report: 12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover — securityweek.com, 10d
The conversation · 0
Sign in to join the conversation.
No comments yet — start the thread.