3.8
CVE-2026-14673
- EPSS 0.27%
- Veröffentlicht 13.08.2026 13:17:44
- Zuletzt bearbeitet 19.08.2026 01:14:45
- CVE-Watchlists
- Unerledigt
PostgreSQL amcheck does not clear untrusted search path
Untrusted search path in PostgreSQL amcheck allows a grantee of amcheck function EXECUTE privilege to execute arbitrary functions as the owners of expression indexes that depend on the search path, via setting a hostile search path before calling the amcheck function. Within major versions 18, 16, 15, and 14, minor versions before PostgreSQL 18.5, 16.15, 15.19, and 14.24 are affected. PostgreSQL 17 is unaffected.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Postgresql ≫ Postgresql Version >= 14.0 < 14.24
Postgresql ≫ Postgresql Version >= 15.0 < 15.19
Postgresql ≫ Postgresql Version >= 16.0 < 16.15
Postgresql ≫ Postgresql Version >= 18.0 < 18.5
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.27% | 0.19 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| f86ef6dc-4d3a-42ad-8f28-e6d5547a5007 | 3.8 | 1.2 | 2.5 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
|
CWE-426 Untrusted Search Path
The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.
https://www.postgresql.org/support/security/CVE-2026-14673/