6.4
CVE-2026-83534
- EPSS 0.19%
- Veröffentlicht 06.09.2026 15:25:41
- Zuletzt bearbeitet 09.09.2026 05:18:19
- Erkennungen
PostgreSQL Anonymizer: Privilege escalation to superuser via anon.anonymize_database_parallel()
PostgreSQL Anonymizer contains a vulnerability in the anon.anonymize_database_parallel() function that allows the owner of a table to run arbitrary code with superuser privilege. The issue is fixed in PostgreSQL Anonymizer 3.2.0 and later versions
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerDALIBO
≫
Produkt
PostgreSQL Anonymizer
Default Statusunaffected
Version
1
Version <
3.2.0
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.19% | 0.089 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| f86ef6dc-4d3a-42ad-8f28-e6d5547a5007 | 6.4 | 0.5 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H
|
CWE-250 Execution with Unnecessary Privileges
The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.
https://gitlab.com/dalibo/postgresql_anonymizer/-/issues/666