CVE-2026-14669PoC(postgresql / postgresql)

MEDIUMCVSS 8.8 · HIGH

Exploit discussion active in current signal (3 latest mentions)

Immediate actions

  • Patch postgresql postgresql systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the party choosing the timezone to execute arbitrary code as the operating system user running the database, via a long POSIX timezone abbreviation. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

RISING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • postgresql

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 10 mentions across 5 observed days
  • Momentum state: rising

What's happening

  • Exploit tool or code specified in 4 signals
  • PoC mentioned or linked in 7 signals
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 8 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 3 mentions (2026-08-24); latest day: 3
  • 10 total mentions across 5 days

Affected systems

Vendors
Products
postgresql

Deep dive

Activity timeline10 mentions / 5d
01223Mentions · 2026-08-13: 1Mentions · 2026-08-17: 1Mentions · 2026-08-18: 2Mentions · 2026-08-24: 3Mentions · 2026-08-25: 3PoC Mentioned / Linked · 2026-08-17: 1PoC Mentioned / Linked · 2026-08-18: 2PoC Mentioned / Linked · 2026-08-24: 3PoC Mentioned / Linked · 2026-08-25: 1Exploit Tool / Code · 2026-08-17: 1Exploit Tool / Code · 2026-08-18: 1Exploit Tool / Code · 2026-08-24: 2Patch / Workaround · 2026-08-13: 1Patch / Workaround · 2026-08-17: 1Patch / Workaround · 2026-08-18: 1Technical Details · 2026-08-13: 1Technical Details · 2026-08-17: 1Technical Details · 2026-08-18: 1Technical Details · 2026-08-24: 2Technical Details · 2026-08-25: 308-1308-1708-1808-2408-25
Signal classification3 categories
PoC
770.0%
Disclosure
220.0%
Patch
110.0%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-08-131
Patch1
2026-08-171
PoC1
2026-08-182
PoC2
2026-08-243
PoC3
2026-08-253
Disclosure2PoC1
Full discourse10 posts
  • V12@v12sec
    PoC

    and here's our poc for postgres server RCE: https://github.com/v12-security/pocs/tree/main/postgresql/server CVE-2026-14669. patched postgreSQL 18.6. poc for client RCE 🔜

    Post summary

    The post provides a PoC for CVE‑2026‑14669, links to GitHub code for server RCE, notes the patch version 18.6, and indicates an upcoming client PoC.

    456130016933.1K
    9.6K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    PoC

    A PostgreSQL vulnerability (CVE-2026-14669, CVSS 8.8) with public PoC exploit code allows remote code execution via to_char. Update now. #PostgreSQL #CVE202614669 #RCE #HeapOverflow #Database #InfoSec http://securityonline.info/postgresql-vulnerability-cve-2026-14669/

    Post summary

    The post announces CVE-2026-14669, a remote code execution issue in PostgreSQL, highlighting that a public PoC exploit exists and urging immediate patching.

    115053222.2K
    13.0K followersView on X
  • dbugs@ptdbugs
    PoC

    A PoC/exploit has been discovered for vulnerability CVE-2026-14669 Vendor: postgresql Product: PostgreSQL Description: Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the party choosing the timezone to execute arbitrary code as the operating system user running the database, via a long POSIX timezone abbreviation. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected. Link: https://github.com/v12-security/pocs/tree/main/postgresql/server #dbugs_vuln

    Post summary

    A proof‑of‑concept exploit for CVE‑2026‑14669 has been published on GitHub, demonstrating a heap buffer overflow in PostgreSQL’s to_char(timestamptz) that allows OS‑level code execution on affected versions.

    01020102.6K
    3.6K followersView on X
  • CCB Alert@CCBalert
    PoC

    Warning: Critical heap buffer overflow in #PostgreSQL. CVE-2026-14669 CVSS: 8.8. Public proof-of-concept (#PoC) enables potential remote code execution (#RCE). Affects versions before 18.5, 17.11, 16.15, 15.19 & 14.24. https://ccb.belgium.be/advisories/warning-vulnerability-postgresql-allows-remote-code-execution-proof-concept-available #Patch #Patch #Patch

    Post summary

    The advisory alerts to a critical heap‑buffer overflow in PostgreSQL (CVE‑2026‑14669) with a public proof‑of‑concept enabling remote code execution, lists affected versions, and provides a link to the official advisory.

    02001384
    7.2K followersView on X
  • VulnTracker@vuln_tracker
    Disclosure

    CVE-2026-14669 — a heap buffer overflow in PostgreSQL's to_char(timestamptz). A long POSIX timezone abbreviation overflows a heap buffer, code runs as the OS user behind Postgres. CVSS 8.8, low privileges, no user interaction. Affects versions before 18.5, 17.11, 16.15, 15.19, 14.24. https://vulntracker.io/blog/postgresql-to-char-heap-buffer-overflow-cve-2026-14669 #PostgreSQL #CVE202614669 #RCE #InfoSec #CyberSecurity #VulnTracker

    Post summary

    This post announces a heap buffer overflow vulnerability in PostgreSQL’s to_char(timestamptz) with relevant technical details and affected versions, but provides no PoC, exploit code, or patch information.

    00011116
    687 followersView on X
  • VulnTracker@vuln_tracker
    Disclosure

    CVE-2026-14669 — a heap buffer overflow in PostgreSQL's to_char(timestamptz). A long POSIX timezone abbreviation overflows a heap buffer, code runs as the OS user behind Postgres. CVSS 8.8, low privileges, no user interaction. Affects versions before 18.5, 17.11, 16.15, 15.19, 14.24. https://vulntracker.io/blog/postgresql-to-char-heap-buffer-overflow-cve-2026-14669/

    Post summary

    The text discloses a heap buffer overflow in PostgreSQL's to_char function, mentions detailed technical aspects and affected versions, but provides no PoC, exploit, or patch information.

    00011152
    687 followersView on X
  • V12@v12sec
    PoC

    poc for postgres server RCE: https://github.com/v12-security/pocs/tree/main/postgresql/server CVE-2026-14669. patched postgreSQL 18.6.

    Post summary

    The text announces a PoC for CVE-2026-14669 involving a PostgreSQL server RCE and notes that PostgreSQL 18.6 has been patched.

    10001275
    8.7K followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨High - PostgreSQL Heap Overflow in to_char(timestamptz) Enables Code Execution (CVE-2026-14669) A heap buffer overflow in PostgreSQL's to_char(timestamptz) lets whoever chooses the timezone trigger memory corruption via a long POSIX timezone abbreviation, resulting in arbitrary code execution as the operating-system user running the database. It requires the ability to supply the timezone value to the function, for example an authenticated user or an app passing user-controlled timezone input, so it's an escalation from database access to OS-level code execution rather than an unauthenticated internet bug. Affects versions before 18.5, 17.11, 16.15, 15.19, and 14.24. CVSS 8.8. 👉Upgrade PostgreSQL to 18.5, 17.11, 16.15, 15.19, or 14.24.

    Post summary

    The post discloses a heap overflow in PostgreSQL’s to_char(timestamptz) that allows OS‑level code execution, includes technical details and CVSS rating, and specifically recommends upgrading to patched versions, but does not mention a PoC, exploit tool, or active exploitation.

    0001097
    288 followersView on X
  • Hephaestvs@Vulcanux_
    PoC

    csirt_it: ‼️ #PoC #PostgreSQL: Disponibile Proof of Concept (PoC) per la vulnerabilità identificata dalla CVE-2026-14669 Rischio: 🔴 Tipologia: 🔸 Remote Code Execution 🔸 Denial of Service 🔗 https://www.acn.gov.it/portale/w/postgresql-disponibile-poc-per-lo-sfruttamento-della-vulnerabilita-cve-2026-14669 ⚠️ Importante mantenere aggiornat… https://t.co/BICyur3uLs

    Post summary

    The tweet announces a Proof of Concept for CVE-2026-14669 with links to the PoC, highlights Remote Code Execution and DoS risk, but does not describe active exploitation or detailed technical exploit code.

    0000033
    632 followersView on X
  • moton@moton
    PoC

    CVE-2026-14669: PoC Code Enables RCE in PostgreSQL - https://securityonline.info/postgresql-vulnerability-cve-2026-14669/

    Post summary

    A Proof of Concept demonstrates that CVE-2026-14669 permits remote code execution in PostgreSQL; a link to the PoC code is provided.

    0000074
    753 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppostgresqlpostgresql---

Explore more