EIP-2026-103808
PRE-CVEPostgreSQL 8.3.6 - Low Cost Function Information Disclosure
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-103808. PoCs published by Andres Freund.
AI-analyzed exploit summary This exploit demonstrates an information disclosure vulnerability in PostgreSQL by creating a function that leaks sensitive data from a restricted view. It uses a custom PL/pgSQL function to bypass access controls and expose column values.
Description
PostgreSQL 8.3.6 - Low Cost Function Information Disclosure
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Andres Freund · textlocalmultiple
https://www.exploit-db.com/exploits/32847
This exploit demonstrates an information disclosure vulnerability in PostgreSQL by creating a function that leaks sensitive data from a restricted view. It uses a custom PL/pgSQL function to bypass access controls and expose column values.
Classification
Working Poc 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target:
PostgreSQL 8.3.6
Auth required
Prerequisites:
Access to a PostgreSQL database with permissions to create functions and query restricted views
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026