PT-2026-23731 · Timescale · Timescaledb

·

CVE-2026-29089

·

Published

2026-03-06

·

Updated

2026-03-07

CVSS v3.1

8.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TimescaleDB versions 2.23.0 through 2.25.1
Description TimescaleDB is a time-series database that functions as a Postgres extension. A flaw exists where PostgreSQL’s use of the search path setting can allow a malicious user to create functions in user-writable schemas. These functions can shadow built-in Postgres functions and be executed instead during extension upgrades, potentially leading to arbitrary code execution. The issue stems from unqualified database object lookups when the search path includes schemas accessible for writing.
Recommendations Upgrade to TimescaleDB version 2.25.2 or later.

Exploit

Fix

Untrusted Search Path

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-29089
GHSA-VGP2-JJ5C-828M

Affected Products

Timescaledb