PT-2026-71484 · Postgresql Global Development Group+2 · Postgresql+2
CVE-2026-18408
·
Published
2026-08-12
·
Updated
2026-09-03
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
PostgreSQL versions prior to 18.5
PostgreSQL versions prior to 17.11
PostgreSQL versions prior to 16.15
PostgreSQL versions prior to 15.19
PostgreSQL versions prior to 14.24
Description
Untrusted data inclusion in
pg dump, pg dumpall, and pg restore (when generating plain-format dumps) allows a malicious superuser of the origin server to inject arbitrary code. This code is executed by the client operating system account running psql during the restore process via psql restrict meta-command input expansion. Although restrict and unrestrict were introduced to block this attack, the unrestrict command itself was found to be sufficient for exploitation.Recommendations
Update PostgreSQL to version 18.5 or later.
Update PostgreSQL to version 17.11 or later.
Update PostgreSQL to version 16.15 or later.
Update PostgreSQL to version 15.19 or later.
Update PostgreSQL to version 14.24 or later.
Fix
DoS
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linuxmint
Postgresql
Ubuntu