Back

HIGH

PostgreSQL logical decoding can dlopen arbitrary file

Published Aug 13, 2026

Description

Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating system account running the server, via the choice of logical decoding plugin. This in turn runs arbitrary code as that account. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Affected products

Remediation

Red Hat statement

Important: This flaw in PostgreSQL's logical decoding feature allows a non-superuser with the REPLICATION privilege to execute arbitrary code. Exploitation requires an attacker to already have significant access to the database, specifically the REPLICATION role, which is not granted by default to typical users, thus reducing the overall risk.

Red Hat mitigation

To mitigate this vulnerability, ensure that the REPLICATION privilege is granted only to highly trusted database superusers. Regularly review user privileges to confirm that non-superuser accounts do not possess the REPLICATION privilege unless absolutely necessary and their activities are closely monitored. If logical decoding is not actively used, consider disabling it to further reduce the attack surface, though specific configuration steps for disabling logical decoding are beyond the scope of this mitigation.

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner PostgreSQL
Published Aug 13, 2026
Updated Aug 29, 2026
Reserved Apr 17, 2026
CISA Vulnrichment
Updated Aug 13, 2026
NVD
Status Modified
Modified Aug 29, 2026
Red Hat
Severity Important
Public date Aug 13, 2026
ENISA EUVD
Assigner PostgreSQL
Published Aug 13, 2026
Updated Aug 29, 2026
Exploited since n/a
EUVD-2026-57857