PostgreSQL auth bypass via logical decoding plugin DLopen in 18.x/17.x
CVE-2026-6471 Published on August 13, 2026

PostgreSQL logical decoding can dlopen arbitrary file
Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating system account running the server, via the choice of logical decoding plugin. This in turn runs arbitrary code as that account. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.

NVD

Weakness Type

What is an AuthZ Vulnerability?

The software does not perform an authorization check when an actor attempts to access a resource or perform an action.

CVE-2026-6471 has been classified to as an AuthZ vulnerability or weakness.


Products Associated with CVE-2026-6471

Want to know whenever a new CVE is published for PostgreSQL? stack.watch will email you.