Home / Sep 05, 2026 / Story
0
#3 SecurityWeek general September 04, 2026 at 12:06 UTC

12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover

By Ionut Arghire

AI Summary

CVE-2026-6471, dubbed PostGREShell, is a 12-year-old logical decoding flaw in PostgreSQL present since version 9.4 (2014) that allows an account with the REPLICATION attribute to execute arbitrary code as the OS user running the database. Affected versions include all PostgreSQL releases before 18.6, 17.11, 16.15, 15.19, and 14.24, meaning unpatched deployments face risks of database takeover and persistent backdoor installation.

Relevance score: 86.0/100

# More from September 05