CVE-2026-11945

MEDIUM

PostgreSQL Anonymizer: SQL injection in the rules import functions

Title source: cna
STIX 2.1

Description

PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a JSON document and placing malicious code inside a particular key-value pair. If a superuser calls the import_database_rules() or import_roles_rules() functions, the malicious code is executed with superuser privileges. The problem is resolved in PostgreSQL Anonymizer 3.1.1 and further versions

References (1)

Core 1

Scores

CVSS v3 6.4
EPSS 0.0020
EPSS Percentile 9.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-89
Status published
Products (1)
DALIBO/PostgreSQL Anonymizer 1 - 3.1.1
Published Jun 11, 2026
Tracked Since Jun 11, 2026