SEPTEMBER 25, 2026
Live Feed
Back to database
Case File

CVE-2026-6476

HIGH · CVSS 7.2 EPSS 0.29%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2026-05-14 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.2. It involves a SQL injection risk.

CVE
CVE-2026-6476
Severity
HIGH
CVSS
7.2
EPSS
0.29%

Original NVD Description

SQL injection in PostgreSQL pg_createsubscriber allows an attacker with pg_create_subscription rights to execute arbitrary SQL as a superuser. The attack takes effect when pg_createsubscriber next runs. Within major versions 17 and 18, minor versions before PostgreSQL 18.4 and 17.10 are affected. Versions before PostgreSQL 17 are unaffected.

Related CVEs

Other vulnerabilities affecting the same vendor(s)