CVE-2026-6476: PostgreSQL

High severity, CVSS 7.2. EPSS: 0.3% chance of exploitation in the next 30 days.

SQL injection in PostgreSQL pg_createsubscriber allows an attacker with pg_create_subscription rights to execute arbitrary SQL as a superuser. The attack takes effect when pg_createsubscriber next runs. Within major versions 17 and 18, minor versions before PostgreSQL 18.4 and 17.10 are affected. Versions before PostgreSQL 17 are unaffected.

Affected products

  • PostgreSQL PostgreSQL: from 17.0, before 17.10 (fixed in 17.10); from 18.0, before 18.4 (fixed in 18.4)

Published 2026-05-14. Last modified 2026-06-17.