PostgreSQL CREATE TYPE does not check multirange schema CREATE privilege
Published May 14, 2026
5.4
MEDIUMCVSS 3.1
EPSS 0.23%
Description
Missing authorization in PostgreSQL CREATE TYPE allows an object creator to hijack other queries that use search_path to find user-defined types, including extension-defined types. That is to say, the victim will execute arbitrary SQL functions of the attacker's choice. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
Affected products
- Vendor n/a Product PostgreSQL Defaultunaffected
Affected
- ≥ 0, < 14.23
- ≥ 15, < 15.18
- ≥ 16, < 16.14
- ≥ 17, < 17.10
- ≥ 18, < 18.4
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| n/a | PostgreSQL | unaffected | Affected
|
- < 14.23
- ≥ 15.0 · < 15.18
- ≥ 16.0 · < 16.14
- ≥ 17.0 · < 17.10
- ≥ 18.0 · < 18.4
No data.
Red Hat Enterprise Linux 10
postgresql16-0:16.14-1.el10_2
Fixed · RHSA-2026:27743
Red Hat Enterprise Linux 10
postgresql18-0:18.4-1.el10_2
Fixed · RHSA-2026:27742
Red Hat Enterprise Linux 10.0 Extended Update Support
postgresql16-0:16.14-1.el10_0
Fixed · RHSA-2026:27718
Red Hat Enterprise Linux 8
postgresql:15-8100020260605152259.489197e6
Fixed · RHSA-2026:26181
Red Hat Enterprise Linux 8
postgresql:16-8100020260530205218.489197e6
Fixed · RHSA-2026:28143
Red Hat Enterprise Linux 8.8 Telecommunications Update Service
postgresql:15-8080020260615085052.63b34585
Fixed · RHSA-2026:26561
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
postgresql:15-8080020260615085052.63b34585
Fixed · RHSA-2026:26561
Red Hat Enterprise Linux 9
postgresql:15-9080020260605124405.rhel9
Fixed · RHSA-2026:28037
Red Hat Enterprise Linux 9
postgresql:16-9080020260605131007.rhel9
Fixed · RHSA-2026:26203
Red Hat Enterprise Linux 9
postgresql:18-9080020260605125734.rhel9
Fixed · RHSA-2026:26204
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
postgresql:15-9020020260625101129.rhel9
Fixed · RHSA-2026:33497
Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions
postgresql:15-9040020260616071806.rhel9
Fixed · RHSA-2026:33441
Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions
postgresql:16-9040020260612132455.rhel9
Fixed · RHSA-2026:26524
Red Hat Enterprise Linux 9.6 Extended Update Support
postgresql:15-9060020260622062902.rhel9
Fixed · RHSA-2026:32983
Red Hat Enterprise Linux 9.6 Extended Update Support
postgresql:16-9060020260612084605.rhel9
Fixed · RHSA-2026:26525
Red Hat Hardened Images
postgresql17-main-17.10-0.1.hum1
Fixed · RHSA-2026:21182
Red Hat Hardened Images
postgresql18-main-18.4-0.1.hum1
Fixed · RHSA-2026:22878
Red Hat Update Infrastructure 5
rhui5/rhua-rhel9:1784795076
Fixed · RHSA-2026:44481
Red Hat Update Infrastructure 5
rhui5/rhua-tp-rhel9:1787241260
Fixed · RHSA-2026:58981
Red Hat Enterprise Linux 6
postgresql
Not affected
Red Hat Enterprise Linux 7
postgresql
Not affected
Red Hat Enterprise Linux 8
postgresql
Not affected
Red Hat Enterprise Linux 9
postgresql
Not affected
Self-service automation portal 2
ansible-automation-platform/bootc-automation-portal-rhel9
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | postgresql16-0:16.14-1.el10_2 | Fixed | RHSA-2026:27743 |
| Red Hat Enterprise Linux 10 | postgresql18-0:18.4-1.el10_2 | Fixed | RHSA-2026:27742 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | postgresql16-0:16.14-1.el10_0 | Fixed | RHSA-2026:27718 |
| Red Hat Enterprise Linux 8 | postgresql:15-8100020260605152259.489197e6 | Fixed | RHSA-2026:26181 |
| Red Hat Enterprise Linux 8 | postgresql:16-8100020260530205218.489197e6 | Fixed | RHSA-2026:28143 |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | postgresql:15-8080020260615085052.63b34585 | Fixed | RHSA-2026:26561 |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | postgresql:15-8080020260615085052.63b34585 | Fixed | RHSA-2026:26561 |
| Red Hat Enterprise Linux 9 | postgresql:15-9080020260605124405.rhel9 | Fixed | RHSA-2026:28037 |
| Red Hat Enterprise Linux 9 | postgresql:16-9080020260605131007.rhel9 | Fixed | RHSA-2026:26203 |
| Red Hat Enterprise Linux 9 | postgresql:18-9080020260605125734.rhel9 | Fixed | RHSA-2026:26204 |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | postgresql:15-9020020260625101129.rhel9 | Fixed | RHSA-2026:33497 |
| Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions | postgresql:15-9040020260616071806.rhel9 | Fixed | RHSA-2026:33441 |
| Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions | postgresql:16-9040020260612132455.rhel9 | Fixed | RHSA-2026:26524 |
| Red Hat Enterprise Linux 9.6 Extended Update Support | postgresql:15-9060020260622062902.rhel9 | Fixed | RHSA-2026:32983 |
| Red Hat Enterprise Linux 9.6 Extended Update Support | postgresql:16-9060020260612084605.rhel9 | Fixed | RHSA-2026:26525 |
| Red Hat Hardened Images | postgresql17-main-17.10-0.1.hum1 | Fixed | RHSA-2026:21182 |
| Red Hat Hardened Images | postgresql18-main-18.4-0.1.hum1 | Fixed | RHSA-2026:22878 |
| Red Hat Update Infrastructure 5 | rhui5/rhua-rhel9:1784795076 | Fixed | RHSA-2026:44481 |
| Red Hat Update Infrastructure 5 | rhui5/rhua-tp-rhel9:1787241260 | Fixed | RHSA-2026:58981 |
| Red Hat Enterprise Linux 6 | postgresql | Not affected | n/a |
| Red Hat Enterprise Linux 7 | postgresql | Not affected | n/a |
| Red Hat Enterprise Linux 8 | postgresql | Not affected | n/a |
| Red Hat Enterprise Linux 9 | postgresql | Not affected | n/a |
| Self-service automation portal 2 | ansible-automation-platform/bootc-automation-portal-rhel9 | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This vulnerability affects PostgreSQL multirange type creation functionality. Red Hat Product Security has assessed this issue as a Moderate severity vulnerability. The vulnerability does not directly provide operating system command execution or PostgreSQL superuser privileges. The impact is limited to the affected database context and depends on application query behavior and schema resolution patterns. Therefore, Red Hat assessed the Confidentiality and Integrity impacts as Low (C:L/I:L), with no demonstrated Availability impact (A:N).
Red Hat mitigation
Red Hat is not aware of a practical temporary workaround that fully mitigates this issue or meets Red Hat Product Security's standards for usability, deployment, applicability, or stability.
References (6)
- https://access.redhat.com/security/cve/CVE-2026-6472 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2477436 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-30282 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-6472
- https://www.cve.org/CVERecord?id=CVE-2026-6472
- https://www.postgresql.org/support/security/CVE-2026-6472/ PatchVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-6472 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2477436 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-30282 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-6472 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-6472 | ||
| https://www.postgresql.org/support/security/CVE-2026-6472/ | PatchVendor Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data