PT-2026-43992 · Sbertech+2 · Pangolin+2
CVE-2026-9617
·
Published
2026-05-27
·
Updated
2026-06-29
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
PostgreSQL Anonymizer versions prior to 3.1.0
Description
An issue allows a user to obtain superuser privileges by creating a table and embedding malicious code within a column identifier. When a superuser invokes the k-anonymity function, the embedded code is executed with superuser permissions. The risk is more significant in PostgreSQL 14 or instances upgraded from PostgreSQL 14 or earlier versions. In PostgreSQL 15 and later, the exploit is limited to users explicitly granted the
CREATE TABLE privilege because creation permissions on the public schema are revoked by default.Recommendations
Update to version 3.1.0 or a later version.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pangolin
Postgresql Anonymizer
Anonymizer