CVE-2026-2004
HIGHCVSS v3.1: 8.8 · EPSS: 0.0050 (38.9 percentile)
Source data as of:
At a glance
- Severity
- HIGH
- CVSS
- 8.8 v3.1 · NVD
- EPSS
- 0.0050 (38.9 percentile) · FIRST.org
- CISA KEV
- No
- Attack conditions (CVSS vector)
- NetworkNo user interaction · Source: NVD Vector
- Affected vendors
- postgresql
- Published
- 2026-02-12 · Modified: 2026-06-30
- References
- Jump to references (8)
CVSS / EPSS / KEV
Source — CVSS: NVD · EPSS: FIRST.org · KEV: CISA. Data & Sources
Description
Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object creator to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.
References
Reference URLs as listed by NVD, grouped by a mechanical match on the link's host/pattern. Labels describe the link type only.
- Reference https://www.postgresql.org/support/security/CVE-2026-2004/
- Distro https://access.redhat.com/errata/RHSA-2026:19009
- Distro https://access.redhat.com/errata/RHSA-2026:19010
- Distro https://access.redhat.com/errata/RHSA-2026:3730
- Distro https://access.redhat.com/errata/RHSA-2026:3887
- Distro https://access.redhat.com/errata/RHSA-2026:3896
- Distro https://access.redhat.com/errata/RHSA-2026:4024
- Distro https://access.redhat.com/errata/RHSA-2026:4059