PT-2026-71484 · Postgresql Global Development Group+2 · Postgresql+2

CVE-2026-18408

·

Published

2026-08-12

·

Updated

2026-09-03

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions PostgreSQL versions prior to 18.5 PostgreSQL versions prior to 17.11 PostgreSQL versions prior to 16.15 PostgreSQL versions prior to 15.19 PostgreSQL versions prior to 14.24
Description Untrusted data inclusion in pg dump, pg dumpall, and pg restore (when generating plain-format dumps) allows a malicious superuser of the origin server to inject arbitrary code. This code is executed by the client operating system account running psql during the restore process via psql restrict meta-command input expansion. Although restrict and unrestrict were introduced to block this attack, the unrestrict command itself was found to be sufficient for exploitation.
Recommendations Update PostgreSQL to version 18.5 or later. Update PostgreSQL to version 17.11 or later. Update PostgreSQL to version 16.15 or later. Update PostgreSQL to version 15.19 or later. Update PostgreSQL to version 14.24 or later.

Fix

DoS

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-95705
BDU:2026-11972
BIT-POSTGRESQL-2026-18408
CVE-2026-18408
ECHO-81A7-2888-C43B
OESA-2026-3420
OESA-2026-3421
OESA-2026-3422
OESA-2026-3423
OESA-2026-3424
OPENSUSE-SU-2026:11552-1
OPENSUSE-SU-2026:11553-1
OPENSUSE-SU-2026:11554-1
OPENSUSE-SU-2026:11555-1
OPENSUSE-SU-2026:11565-1
OPENSUSE-SU-2026:21699-1
OPENSUSE-SU-2026:21700-1
OPENSUSE-SU-2026:21701-1
OPENSUSE-SU-2026:21702-1
OPENSUSE-SU-2026:21703-1
SUSE-SU-2026:3793-1
SUSE-SU-2026:3794-1
SUSE-SU-2026:3940-1
SUSE-SU-2026:3941-1
SUSE-SU-2026:3942-1
SUSE-SU-2026:3943-1
SUSE-SU-2026:3944-1
USN-8653-1

Affected Products

Linuxmint
Postgresql
Ubuntu