As cited
Copy frozen at (site build).
vulnerabilities
PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution
PostgreSQL released patches for CVE-2026-6471, a 12-year-old vulnerability in logical decoding that allows accounts with REPLICATION privileges to execute arbitrary code with database server operating system permissions. The flaw affects versions 18.5 and earlier, 17.10 and earlier, 16.14 and earlier, 15.18 and earlier, and 14.23 and earlier.
Why it matters: Database administrators running affected PostgreSQL versions must patch immediately, as any user granted REPLICATION role can gain full system-level code execution on the database host.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution
PostgreSQL released patches for CVE-2026-6471, a 12-year-old vulnerability in logical decoding that allows accounts with REPLICATION privileges to execute arbitrary code with database server operating system permissions. The flaw affects versions 18.5 and earlier, 17.10 and earlier, 16.14 and earlier, 15.18 and earlier, and 14.23 and earlier.
Why it matters: Database administrators running affected PostgreSQL versions must patch immediately, as any user granted REPLICATION role can gain full system-level code execution on the database host.
- Source published
- First seen by Cybersecurity Tracker