Retour aux alertes CVE
CVE-2026-6471 HIGH CVSS 7.2

CVE-2026-6471 HIGH

Publiée 3 weeks ago Fiche NVD officielle

Qu'est-ce que c'est ?

Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating system account running the server, via the choice of logical decoding plugin. This in turn runs arbitrary code as that account. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.

Technologies affectées

Non précisé par la fiche NVD.

Recommandation

Vérifie la disponibilité d'un correctif pour la technologie concernée et applique-le dès que possible. Consulte la fiche NVD pour les références officielles du fournisseur.

Exploits publics connus (3)

0xBlackash/CVE-2026-6471

CVE-2026-6471

goldendivider/cve-2026-6471-postgres-logical-decoding-dlopen

postgres CVE-2026-6471 Exploit

HORKimhab/CVE-2026-6471

CVE-2026-6471 - Draft or TODO

Usage responsable : ces liens pointent vers des dépôts publics GitHub à but éducatif ou de test d'intrusion autorisé. N'utilise ces PoC que sur des systèmes que tu es autorisé à tester.