CVE-2026-2004

HIGH

PostgreSQL <18.2, 17.8, 16.12, 15.16, 14.21 - RCE

Title source: llm
STIX 2.1

Description

Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object creator to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.

Scores

CVSS v3 8.8
EPSS 0.0006
EPSS Percentile 18.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-1287
Status published
Products (1)
postgresql/postgresql 14.0 - 14.21
Published Feb 12, 2026
Tracked Since Feb 18, 2026