PT-2026-71470 · Postgresql Global Development Group+2 · Postgresql+2
CVE-2026-14672
·
Published
2026-08-12
·
Updated
2026-09-03
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
PostgreSQL versions 16.0 through 16.14
PostgreSQL versions 17.0 through 17.10
PostgreSQL versions 18.0 through 18.4
Description
A discrepancy in the responses of the SCRAM authentication subsystem allows an unauthenticated remote attacker to verify the existence of a user. This is achieved by observing the
scram iterations count, as the system reports the default value for nonexistent users, whereas existing users may have a non-default count.Recommendations
Update PostgreSQL version 16 to 16.15.
Update PostgreSQL version 17 to 17.11.
Update PostgreSQL version 18 to 18.5.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linuxmint
Postgresql
Ubuntu