CVE-2026-65314

MEDIUM

Electric Postgres Sync Excluded-Column Value Inference via Subset Where Clauses

Title source: cna
STIX 2.1

Description

Electric Postgres Sync versions below 1.6.10 contains an information disclosure vulnerability that allows attackers to infer the values of excluded columns by crafting subset where clause conditions against shape responses. Attackers can observe whether subset where conditions match rows to deduce sensitive field data even though those columns are not returned in shape responses, bypassing column-based access restrictions.

References (3)

Core 3

Scores

CVSS v3 4.3
EPSS 0.0023
EPSS Percentile 13.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-203
Status published
Products (1)
ElectricSQL/Electric Postgres Sync < 1.6.10
Published Jul 21, 2026
Tracked Since Jul 22, 2026