CVE-2016-2193: PostgreSQL

High severity, CVSS 7.5. EPSS: 1.8% chance of exploitation in the next 30 days.

PostgreSQL before 9.5.x before 9.5.2 does not properly maintain row-security status in cached plans, which might allow attackers to bypass intended access restrictions by leveraging a session that performs queries as more than one role.

Affected products

  • PostgreSQL PostgreSQL: version 9.5 only; version 9.5.1 only

Published 2016-04-11. Last modified 2026-06-17.