Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-10976

19
FAUCET Score

CVE-2024-10976 is a medium-severity vulnerability in PostgreSQL affecting versions prior to 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21. It stems from incomplete tracking of tables with row security, allowing a reused query to access or modify unintended rows when user IDs change, particularly with role-specific policies. This can lead to unauthorized data exposure or modification (CVSS 5.4, C:L, I:L). Exploitation requires an attacker to tailor an attack to specific application patterns, and there is currently no evidence of active exploitation, public exploit code, or significant community discussion.

Impacted Technologies

VendorProductVersion(s)CPE
>= 12.0, < 12.21CPE matchmatch criteria
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*
>= 13.0, < 13.17CPE matchmatch criteria
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*
>= 14.0, < 14.14CPE matchmatch criteria
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*
>= 15.0, < 15.9CPE matchmatch criteria
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*
>= 16.0, < 16.5CPE matchmatch criteria
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

4.2MEDIUM

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
1.6
Impact Score
2.5
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.79%
Probability of exploitation in next 30 days
EPSS Percentile
52.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0079 is in the 64th percentile among its peer group of 21,957 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (24)

beckhoffpatch availablevia llm_extracted
Fixed in: 17.1, 16.5, 15.9, 14.14
View patch
dhis2patch availablevia llm_extracted
Fixed in: 17.1, 16.5, 15.9, 14.14
View patch
fortinetpatch availablevia llm_extracted
Fixed in: 17.1, 16.5, 15.9, 14.14
View patch
microsoftpatch availablevia msrc
Product: azl3 postgresql 16.4-2 on Azure Linux 3.0Fixed in: 16.5-1
microsoftpatch availablevia msrc
Product: 17174-16823Fixed in: 14.14-1
microsoftpatch availablevia msrc
Product: 19831-17086Fixed in: 14.14-1
microsoftpatch availablevia msrc
Product: 17259-17086Fixed in: 14.14-1
microsoftpatch availablevia msrc
Product: 17566-17084Fixed in: 16.5-1
microsoftpatch availablevia msrc
Product: 19835-17084Fixed in: 16.5-1
microsoftpatch availablevia msrc
Product: cbl2 postgresql 14.14-1 on CBL Mariner 2.0Fixed in: 14.14-1
microsoftpatch availablevia msrc
Product: cbl2 postgresql 14.13-1 on CBL Mariner 2.0Fixed in: 14.14-1
microsoftpatch availablevia msrc
Product: azl3 postgresql 16.5-1 on Azure Linux 3.0Fixed in: 16.5-1
miniopatch availablevia llm_extracted
Fixed in: 17.1, 16.5, 15.9, 14.14
View patch
navidromepatch availablevia llm_extracted
Fixed in: 17.1, 16.5, 15.9, 14.14
View patch
netscoutpatch availablevia llm_extracted
Fixed in: 17.1, 16.5, 15.9, 14.14
View patch
new_relicpatch availablevia llm_extracted
Fixed in: 17.1, 16.5, 15.9, 14.14
View patch
nvidiapatch availablevia llm_extracted
Fixed in: 17.1, 16.5, 15.9, 14.14
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: postgresql:15-8100020241122084744.489197e6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: postgresql:13-8100020241122084628.489197e6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: postgresql:12-8100020241122084405.489197e6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: postgresql:16-8100020241122085009.489197e6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: postgresql:15-9050020241122141928.rhel9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: postgresql:16-9050020241122142517.rhel9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: postgresql-0:13.18-1.el9_5
View patch

Vendor Advisories (10)

redhatCVE-2024-10976Moderate

postgresql: PostgreSQL row security below e.g. subqueries disregards user ID changes

Nov 14, 2024
microsoft2024-Nov/CVE-2024-10976Moderate

PostgreSQL row security below e.g. subqueries disregards user ID changes

Nov 12, 2024
fortinetllm-fortinet-398adac076dcdaffMEDIUM

PostgreSQL row security below e.g. subqueries disregards user ID changes

Jan 1, 2024
new_relicllm-new_relic-e08c977766409ccaMEDIUM

PostgreSQL row security below e.g. subqueries disregards user ID changes

dhis2llm-dhis2-2074250c8c4d7622MEDIUM

PostgreSQL row security below e.g. subqueries disregards user ID changes

miniollm-minio-3d36f9727b7fae80MEDIUM

PostgreSQL row security below e.g. subqueries disregards user ID changes

navidromellm-navidrome-03855e194a8b0988MEDIUM

PostgreSQL row security below e.g. subqueries disregards user ID changes

nvidiallm-nvidia-41b56945fe7d2b44MEDIUM

PostgreSQL row security below e.g. subqueries disregards user ID changes

beckhoffllm-beckhoff-3553931bcf2be6bfMEDIUM

PostgreSQL row security below e.g. subqueries disregards user ID changes

netscoutllm-netscout-7229545433b0e53cMEDIUM

PostgreSQL row security below e.g. subqueries disregards user ID changes

References

lists.debian.org / debian-lts-announce/2024/11/msg00011.html
security.netapp.com / advisory/ntap-20250509-0010
postgresql.org / support/security/CVE-2024-10976
Vendor Advisory