PT-2026-71470 · Postgresql Global Development Group+2 · Postgresql+2

CVE-2026-14672

·

Published

2026-08-12

·

Updated

2026-09-03

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions PostgreSQL versions 16.0 through 16.14 PostgreSQL versions 17.0 through 17.10 PostgreSQL versions 18.0 through 18.4
Description A discrepancy in the responses of the SCRAM authentication subsystem allows an unauthenticated remote attacker to verify the existence of a user. This is achieved by observing the scram iterations count, as the system reports the default value for nonexistent users, whereas existing users may have a non-default count.
Recommendations Update PostgreSQL version 16 to 16.15. Update PostgreSQL version 17 to 17.11. Update PostgreSQL version 18 to 18.5.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-95702
BDU:2026-11958
BIT-POSTGRESQL-2026-14672
CVE-2026-14672
ECHO-1137-4F23-2F4E
OESA-2026-3423
OESA-2026-3424
OPENSUSE-SU-2026:11554-1
OPENSUSE-SU-2026:11555-1
OPENSUSE-SU-2026:11565-1
OPENSUSE-SU-2026:21701-1
OPENSUSE-SU-2026:21702-1
OPENSUSE-SU-2026:21703-1
SUSE-SU-2026:3794-1
SUSE-SU-2026:3942-1
SUSE-SU-2026:3943-1
USN-8653-1

Affected Products

Linuxmint
Postgresql
Ubuntu