CVE 8.8 HIGH

PostgreSQL pg_basebackup and pg_rewind can overwrite unrelated files of origin superuser choice_CVE-2026-6475

8.8 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Description

Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

AI Analysis

Symlink following vulnerability in PostgreSQL pg_basebackup and pg_rewind allows an origin superuser to overwrite local files, potentially hijacking the operating system account.

Basic Information

ID CVE-2026-6475
Source PostgreSQL
Published May 14, 2026 at 13:00

Affected Product

Vendor n/a
Product PostgreSQL
Version 18
Affected Versions n/a PostgreSQL 18
n/a PostgreSQL 17
n/a PostgreSQL 16
n/a PostgreSQL 15
n/a PostgreSQL 0

CWE Classification

AI Assessment

AI Score 8.8 / 10
AI Severity High
Vendor PostgreSQL Global Development Group
Product PostgreSQL
Version 18.4, 17.10, 16.14, 15.18, 14.23

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.