CVE-2026-2006 is a critical vulnerability in PostgreSQL affecting versions prior to 18.2, 17.8, 16.12, 15.16, and 14.21. It stems from a missing validation of multibyte character length, allowing a database user to trigger a buffer overrun via crafted queries. This flaw carries a CVSS score of 8.8 (High), indicating a network-exploitable vulnerability with low privileges that can lead to complete compromise of confidentiality, integrity, and availability, including arbitrary code execution as the operating system user running the database. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion and media coverage, suggesting awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 14.0, < 14.21CPE matchmatch criteria | cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* | ||
>= 15.0, < 15.16CPE matchmatch criteria | cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* | ||
>= 16.0, < 16.12CPE matchmatch criteria | cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* | ||
>= 17.0, < 17.8CPE matchmatch criteria | cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* | ||
>= 18.0, < 18.2CPE matchmatch criteria | cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
PostgreSQL vulnerabilities
Mar 4, 2026postgresql: PostgreSQL missing validation of multibyte character length executes arbitrary code
Feb 12, 2026PostgreSQL missing validation of multibyte character length executes arbitrary code
Jan 1, 2026PostgreSQL missing validation of multibyte character length executes arbitrary code
PostgreSQL missing validation of multibyte character length executes arbitrary code
PostgreSQL missing validation of multibyte character length executes arbitrary code
PostgreSQL missing validation of multibyte character length executes arbitrary code
PostgreSQL missing validation of multibyte character length executes arbitrary code
PostgreSQL missing validation of multibyte character length executes arbitrary code
PostgreSQL missing validation of multibyte character length executes arbitrary code