CVE-2026-15741Patch(postgresql / postgresql)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch postgresql postgresql systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

SQL injection in PostgreSQL EXTRACT() deparse allows an object owner to execute arbitrary SQL as a superuser via a hostile object definition. Attacks affect expression deparse consumers broadly, including pg_dump, psql commands like \sf, and any similar usage in non-core tools. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • postgresql

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
postgresql

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-17: 1Patch / Workaround · 2026-08-17: 108-17
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
Full discourse1 post
  • セキュリティ対策Lab@securityLab_jp
    Patch

    PostgreSQL、28件の脆弱性を修正、CVSS 8.8は14件(CVE-2026-15741 他) https://rocket-boys.co.jp/security-measures-lab/postgresql-security-update-vulnerabilities-cve-2026-15741/ #セキュリティ対策Lab #security #securitynews #脆弱性

    Post summary

    The post announces that 28 PostgreSQL vulnerabilities, including CVE‑2026‑15741, have been patched, but provides no technical exploitation details or evidence of active attacks.

    00001124
    548 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppostgresqlpostgresql---

Explore more