#3
SecurityWeek
general
September 04, 2026 at 12:06 UTC
12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover
By Ionut Arghire
AI Summary
CVE-2026-6471, dubbed PostGREShell, is a 12-year-old logical decoding flaw in PostgreSQL present since version 9.4 (2014) that allows an account with the REPLICATION attribute to execute arbitrary code as the OS user running the database. Affected versions include all PostgreSQL releases before 18.6, 17.11, 16.15, 15.19, and 14.24, meaning unpatched deployments face risks of database takeover and persistent backdoor installation.
Relevance score: 86.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →