CVE-2026-2006

HIGH

PostgreSQL 14.0-14.20 - Remote Code Execution via Multibyte Character Length Mismanagement

Title source: llm
STIX 2.1

Description

Missing validation of multibyte character length in PostgreSQL text manipulation allows a database user to issue crafted queries that achieve a buffer overrun. That suffices to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.

References (34)

Core 34
Core References

Scores

CVSS v3 8.8
EPSS 0.0108
EPSS Percentile 61.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-1285 CWE-129
Status published
Products (6)
None/PostgreSQL < 14.21
None/PostgreSQL 15 - 15.16
None/PostgreSQL 16 - 16.12
None/PostgreSQL 17 - 17.8
None/PostgreSQL 18 - 18.2
postgresql/postgresql 14.0 - 14.21
Published Feb 12, 2026
Tracked Since Feb 18, 2026