12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover

12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover
Cyera says PostgreSQL versions from 9.4 through 18 are affected by CVE-2026-6471, also called PostGREShell, a severe flaw that can let low-privileged attackers achieve remote code execution, privilege escalation, and persistent superuser access. The issue is patched in PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24, and organizations should update immediately and review Replication accounts. #PostgreSQL #CVE-2026-6471 #PostGREShell

Keypoints

  • Cyera identified a severe PostgreSQL flaw named PostGREShell.
  • The vulnerability is tracked as CVE-2026-6471 with a CVSS score of 7.2.
  • Attackers with Replication privileges can trigger remote code execution and privilege escalation.
  • The bug stems from missing authorization in logical decoding and unsafe plugin loading.
  • Users should patch PostgreSQL and remove unnecessary Replication privileges.

Read More: https://www.securityweek.com/12-year-old-postgresql-vulnerability-enables-database-server-takeover/