CVE-2026-2004

HIGH

PostgreSQL <18.2, 17.8, 16.12, 15.16, 14.21 - RCE

Title source: llm
STIX 2.1

Description

Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object creator to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.

References (34)

Core 34
Core References

Scores

CVSS v3 8.8
EPSS 0.0078
EPSS Percentile 52.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-1287
Status published
Products (6)
None/PostgreSQL < 14.21
None/PostgreSQL 15 - 15.16
None/PostgreSQL 16 - 16.12
None/PostgreSQL 17 - 17.8
None/PostgreSQL 18 - 18.2
postgresql/postgresql 14.0 - 14.21
Published Feb 12, 2026
Tracked Since Feb 18, 2026