12-year-old PostgreSQL vulnerability allows database and server takeover

PostgreSQL releases since 2014 contain a serious vulnerability that could allow a low-privileged attacker to take over databases and servers, cybersecurity firm Cyera reported.

An open source relational database system offering support for both relational (SQL) and non-relational (JSON) queries, PostgreSQL is one of the most popular databases used by tens of thousands of companies, including large enterprises.

Tracked as CVE-2026-6471 (CVSS score of 7.2) and called PostGREShell, the newly identified security flaw can be used for remote code execution and privilege escalation.

It is described as a missing permission in database logical decoding and can be used by attackers who have replication privileges to load any file visible to the operating system account running the server through the logical decoding plugin.

postgreSQL, Cyera explainsuses a special replication protocol to synchronize multiple replicas of each primary database for backup and recovery. This requires an account with the replication attribute and is provided to each connected backup tool, server, pipeline, and monitoring utility.

Changes are logged by local replication as table events so that external tools can read them, which they do by creating a logical replication slot and naming an output plugin that is loaded from PostgreSQL to format the stream.

Advertising. Scroll to continue reading.

When a plugin is loaded, PostgreSQL runs its init function with the privileges of the server process. To prevent abuse, non-superusers can only load add-ons from an administrator-controlled directory.

Cyera discovered that the plugin name is passed directly to the loader, without verification or sanitization, allowing an attacker to pass the loader a full filesystem path that is served to dlopen(), the C/C++ function used to dynamically load shared libraries.

“The replication protocol parser accepts almost any character in a double-quoted plugin name: slashes, backslashes, periods, ../ traversals, even Windows UNC paths,” notes Cyera.

This allows an attacker to load and execute any file via dlopen(), executing the file with the privileges of the postgres system user.

“Code loaded via dlopen() runs in the same address space as PostgreSQL, with no sandboxing and no internal API call checks. The server simply trusts any code that has been loaded,” explains Cyera.

“So the plugin calls an internal function to become the boot superuser for the session, then writes directly to pg_authid, the directory table that defines who the superuser is, and turns each privilege flag to true,” the company continues.

At this point, the attacker has gained permanent superuser privileges: they can access any table in any database, execute OS commands, read private keys, and write files to any location that the postgres process can access.

According to Cyera, the plugin can also deploy backdoor mechanisms: it can enable passwordless connections, copy to a stable location and register to be reloaded in each new backend, and can reapply the superuser’s change even if it is rolled back.

“PostGREShell turns replication credentials that no one cares about into a code execution, superuser, and permanent database backdoor behind much of the Internet. Every version from 9.4 to 18 is affected (we confirmed it on 18.2), and logical replication is now a standard production installation, so the vulnerable path exists almost anywhere PostgreSQL is running,” notes Cyera.

CVE-2026-6471 is patched in PostgreSQL versions 18.6, 17.11, 16.15, 15.19, and 14.24. Organizations are advised to update their replicas as soon as possible, audit their replication accounts, and remove the replication attribute from any account that does not need it.

Related: Rockwell Automation has patched over a dozen product vulnerabilities

Related: OpenLeash adds human verification to the risky actions of an AI agent

Related: Threat Actor hacks 14,000 IP cameras in Ukraine and Russia

Related: New HollowGraph malware abuses Microsoft 365 calendar for C&C communication

Leave a Reply

Your email address will not be published. Required fields are marked *