PT-2026-43992 · Sbertech+2 · Pangolin+2

CVE-2026-9617

·

Published

2026-05-27

·

Updated

2026-06-29

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PostgreSQL Anonymizer versions prior to 3.1.0
Description An issue allows a user to obtain superuser privileges by creating a table and embedding malicious code within a column identifier. When a superuser invokes the k-anonymity function, the embedded code is executed with superuser permissions. The risk is more significant in PostgreSQL 14 or instances upgraded from PostgreSQL 14 or earlier versions. In PostgreSQL 15 and later, the exploit is limited to users explicitly granted the CREATE TABLE privilege because creation permissions on the public schema are revoked by default.
Recommendations Update to version 3.1.0 or a later version.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-9617

Affected Products

Pangolin
Postgresql Anonymizer
Anonymizer