PostgreSQL logical decoding can dlopen arbitrary file
Published Aug 13, 2026
7.2
HIGHCVSS 3.1
EPSS 0.53%
Description
Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating system account running the server, via the choice of logical decoding plugin. This in turn runs arbitrary code as that account. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Affected products
- Vendor n/a Product PostgreSQL Defaultunaffected
- Version 0StatusaffectedConstraints<14.24
- Version 15StatusaffectedConstraints<15.19
- Version 16StatusaffectedConstraints<16.15
- Version 17StatusaffectedConstraints<17.11
- Version 18StatusaffectedConstraints<18.6
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| n/a | PostgreSQL | unaffected |
|
- ≥ 14.0 · < 14.24
- ≥ 15.0 · < 15.19
- ≥ 16.0 · < 16.15
- ≥ 17.0 · < 17.11
- ≥ 18.0 · < 18.5
No data.
Red Hat Enterprise Linux 10
postgresql18-0:18.6-1.el10_2
Fixed · RHSA-2026:67280
Red Hat Enterprise Linux 9
postgresql:16-9080020260907191505.rhel9
Fixed · RHSA-2026:67491
Red Hat Enterprise Linux 9
postgresql:18-9080020260914093252.rhel9
Fixed · RHSA-2026:67848
Red Hat Enterprise Linux 10
postgresql16
Affected
Red Hat Enterprise Linux 6
postgresql
Not affected
Red Hat Enterprise Linux 7
postgresql
Not affected
Red Hat Enterprise Linux 8
postgresql:12/postgresql
Affected
Red Hat Enterprise Linux 8
postgresql:15/postgresql
Affected
Red Hat Enterprise Linux 8
postgresql:16/postgresql
Affected
Red Hat Enterprise Linux 9
postgresql
Affected
Red Hat Enterprise Linux 9
postgresql:15/postgresql
Affected
Red Hat Hardened Images
postgresql17
Not affected
Red Hat Hardened Images
postgresql18
Not affected
Self-service automation portal 2
ansible-automation-platform/bootc-automation-portal-rhel9
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | postgresql18-0:18.6-1.el10_2 | Fixed | RHSA-2026:67280 |
| Red Hat Enterprise Linux 9 | postgresql:16-9080020260907191505.rhel9 | Fixed | RHSA-2026:67491 |
| Red Hat Enterprise Linux 9 | postgresql:18-9080020260914093252.rhel9 | Fixed | RHSA-2026:67848 |
| Red Hat Enterprise Linux 10 | postgresql16 | Affected | n/a |
| Red Hat Enterprise Linux 6 | postgresql | Not affected | n/a |
| Red Hat Enterprise Linux 7 | postgresql | Not affected | n/a |
| Red Hat Enterprise Linux 8 | postgresql:12/postgresql | Affected | n/a |
| Red Hat Enterprise Linux 8 | postgresql:15/postgresql | Affected | n/a |
| Red Hat Enterprise Linux 8 | postgresql:16/postgresql | Affected | n/a |
| Red Hat Enterprise Linux 9 | postgresql | Affected | n/a |
| Red Hat Enterprise Linux 9 | postgresql:15/postgresql | Affected | n/a |
| Red Hat Hardened Images | postgresql17 | Not affected | n/a |
| Red Hat Hardened Images | postgresql18 | Not affected | n/a |
| Self-service automation portal 2 | ansible-automation-platform/bootc-automation-portal-rhel9 | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Important: This flaw in PostgreSQL's logical decoding feature allows a non-superuser with the REPLICATION privilege to execute arbitrary code. Exploitation requires an attacker to already have significant access to the database, specifically the REPLICATION role, which is not granted by default to typical users, thus reducing the overall risk.
Red Hat mitigation
To mitigate this vulnerability, ensure that the REPLICATION privilege is granted only to highly trusted database superusers. Regularly review user privileges to confirm that non-superuser accounts do not possess the REPLICATION privilege unless absolutely necessary and their activities are closely monitored. If logical decoding is not actively used, consider disabling it to further reduce the attack surface, though specific configuration steps for disabling logical decoding are beyond the scope of this mitigation.
References (6)
- https://access.redhat.com/security/cve/CVE-2026-6471 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2515307 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-57857 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-6471
- https://www.cve.org/CVERecord?id=CVE-2026-6471
- https://www.postgresql.org/support/security/CVE-2026-6471/ Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-6471 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2515307 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-57857 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-6471 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-6471 | ||
| https://www.postgresql.org/support/security/CVE-2026-6471/ | Vendor Advisory |
Change history (0)
No recorded changes yet.