8.8
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Description
Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object creator to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.
AI Analysis
Arbitrary code execution in PostgreSQL intarray extension due to missing input validation
Basic Information
ID
CVE-2026-2004
Source
PostgreSQL
Published
Feb 12, 2026 at 13:00
Modified
Feb 12, 2026 at 14:32
Affected Product
Vendor
n/a
Product
PostgreSQL
Version
18
Affected Versions
n/a PostgreSQL 18
n/a PostgreSQL 17
n/a PostgreSQL 16
n/a PostgreSQL 15
n/a PostgreSQL 0
n/a PostgreSQL 17
n/a PostgreSQL 16
n/a PostgreSQL 15
n/a PostgreSQL 0
CWE Classification
AI Assessment
AI Score
8.8 / 10
AI Severity
High
Vendor
PostgreSQL Global Development Group
Product
PostgreSQL
Version
18.2, 17.8, 16.12, 15.16, 14.21