CVE-2026-2006

HIGH

PostgreSQL <18.2-14.21 - RCE

Title source: llm
STIX 2.1

Description

Missing validation of multibyte character length in PostgreSQL text manipulation allows a database user to issue crafted queries that achieve a buffer overrun. That suffices to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.

Scores

CVSS v3 8.8
EPSS 0.0004
EPSS Percentile 11.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-129
Status published
Products (1)
postgresql/postgresql 14.0 - 14.21
Published Feb 12, 2026
Tracked Since Feb 18, 2026