Back

MEDIUM

PostgreSQL CREATE TYPE does not check multirange schema CREATE privilege

Published May 14, 2026

Description

Missing authorization in PostgreSQL CREATE TYPE allows an object creator to hijack other queries that use search_path to find user-defined types, including extension-defined types. That is to say, the victim will execute arbitrary SQL functions of the attacker's choice. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

Affected products

Remediation

Red Hat statement

This vulnerability affects PostgreSQL multirange type creation functionality. Red Hat Product Security has assessed this issue as a Moderate severity vulnerability. The vulnerability does not directly provide operating system command execution or PostgreSQL superuser privileges. The impact is limited to the affected database context and depends on application query behavior and schema resolution patterns. Therefore, Red Hat assessed the Confidentiality and Integrity impacts as Low (C:L/I:L), with no demonstrated Availability impact (A:N).

Red Hat mitigation

Red Hat is not aware of a practical temporary workaround that fully mitigates this issue or meets Red Hat Product Security's standards for usability, deployment, applicability, or stability.

References (6)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner PostgreSQL
Published May 14, 2026
Updated May 14, 2026
Reserved Apr 17, 2026

CISA Vulnrichment

Updated May 14, 2026

NVD

Status Analyzed
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date May 14, 2026
Bugzilla 2477436

ENISA EUVD

Assigner PostgreSQL
Published May 14, 2026
Updated May 14, 2026

GitHub

No data