Back

HIGH

PostgreSQL type confusion in cursor CLOSE + DECLARE executes arbitrary code

Published Aug 13, 2026

Description

Type confusion in PostgreSQL "portal"/cursor lifecycle allows a user to execute arbitrary code as the operating system user running the database, via re-creation of a cursor or other portal with different types. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Affected products

Remediation

Red Hat statement

This is an Important vulnerability in PostgreSQL. A type confusion flaw in the cursor lifecycle allows a low-privileged authenticated database user to execute arbitrary code as the operating system user running the database. This can lead to a complete compromise of the database system, making it a significant risk in typical Red Hat deployments where PostgreSQL instances are exposed to authenticated users.

Red Hat mitigation

To mitigate this vulnerability, restrict direct database access strictly to trusted roles and minimize multi-tenant database scenarios where untrusted users can execute arbitrary SQL. Monitor database audit logs for anomalous or high-frequency cursor lifecycle activities involving unexpected CLOSE and DECLARE operations.

Weaknesses (1)

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner PostgreSQL
Published Aug 13, 2026
Updated Aug 29, 2026
Reserved Jul 20, 2026
CISA Vulnrichment
Updated Aug 13, 2026
NVD
Status Modified
Modified Aug 29, 2026
Red Hat
Severity Important
Public date Aug 13, 2026
ENISA EUVD
Assigner PostgreSQL
Published Aug 13, 2026
Updated Aug 29, 2026
Exploited since n/a
EUVD-2026-57849