CVE-2026-2004Patch(postgresql / postgresql)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch postgresql postgresql systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object creator to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.

0.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1287

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • postgresql

Threat summary

  • Patch or workaround signal is available
  • 14 mentions across 10 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 10 signals
  • Technical details provided in 10 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 9d ago at 3 mentions (2026-02-12); latest day: 1
  • 14 total mentions across 10 days

Affected systems

Vendors
Products
postgresql

Deep dive

Activity timeline14 mentions / 10d
01223Mentions · 2026-02-12: 3Mentions · 2026-02-13: 1Mentions · 2026-02-14: 1Mentions · 2026-02-17: 2Mentions · 2026-02-18: 1Mentions · 2026-02-19: 1Mentions · 2026-02-25: 1Mentions · 2026-03-06: 1Mentions · 2026-03-12: 2Mentions · 2026-05-12: 1Patch / Workaround · 2026-02-12: 1Patch / Workaround · 2026-02-13: 1Patch / Workaround · 2026-02-14: 1Patch / Workaround · 2026-02-18: 1Patch / Workaround · 2026-02-19: 1Patch / Workaround · 2026-02-25: 1Patch / Workaround · 2026-03-06: 1Patch / Workaround · 2026-03-12: 2Patch / Workaround · 2026-05-12: 1Technical Details · 2026-02-12: 3Technical Details · 2026-02-14: 1Technical Details · 2026-02-17: 1Technical Details · 2026-02-25: 1Technical Details · 2026-03-06: 1Technical Details · 2026-03-12: 2Technical Details · 2026-05-12: 102-1202-1302-1402-1702-1802-1902-2503-0603-1205-12
Signal classification3 categories
Patch
964.3%
Disclosure
428.6%
General
17.1%
Referenced assets14 URLs
Classification over time
DateTotalLabels
2026-02-123
Disclosure2Patch1
2026-02-131
Patch1
2026-02-141
Patch1
2026-02-172
Disclosure1General1
2026-02-181
Patch1
2026-02-191
Patch1
2026-02-251
Disclosure1
2026-03-061
Patch1
2026-03-122
Patch2
2026-05-121
Patch1
Full discourse14 posts
  • Mehmet INCE@mdisec
    Disclosure

    CVE-2026-2006 PostgreSQL missing validation of multibyte character length executes arbitrary code Missing validation of multibyte character length in PostgreSQL text manipulation allows a database user to issue crafted queries that achieve a buffer overrun. That suffices to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected. The PostgreSQL project thanks Paul Gerste and Moritz Sanft, as part of http://zeroday.cloud, for reporting this problem. https://cvefeed.io/vuln/detail/CVE-2026-2004

    Post summary

    PostgreSQL versions 14‑18 are vulnerable to CVE‑2026‑2006 due to missing multibyte character length validation, enabling a buffer overrun and arbitrary code execution; no PoC, exploit, or patch details are provided.

    01911646319.3K
    33.1K followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos PostgreSQL ❗ CVE-2026-2004 ❗ CVE-2026-2005 ❗ CVE-2026-2006 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-postgresql/ https://t.co/GCOXi3X40y

    Post summary

    The post simply lists three PostgreSQL CVE identifiers and links to a CERT page for additional information, without providing any technical, exploit, or patch details.

    02073764
    6.6K followersView on X
  • Grok@grok
    Disclosure

    The latest Postgres CVEs (fixed in the Feb 12 2026 release: 18.2, 17.8, 16.12, 15.16, 14.21) are: - CVE-2026-2003: oidvector memory disclosure (medium) - CVE-2026-2004: intarray selectivity estimator exec code (high) - CVE-2026-2005: pgcrypto heap buffer overflow exec code (high) - CVE-2026-2006: multibyte char length buffer overrun exec code (high) - CVE-2026-2007: pg_trgm heap buffer overflow (high, 18.x only) AWS RDS/Aurora has no public patches or timeline yet.

    Post summary

    The post announces a set of new PostgreSQL CVEs, details their technical nature, and notes that they are fixed in an upcoming release, while highlighting the absence of patches for AWS RDS/Aurora.

    1000285
    8.2M followersView on X
  • Mydbops@MydbopsOfficial
    Patch

    🚨 PostgreSQL CVE-2026-2004 (CVSS 8.8) Critical RCE flaw affecting PostgreSQL 14–18. Patch now: 18.2 | 17.8 | 16.12 | 15.16 | 14.21 https://www.postgresql.org/support/security/CVE-2026-2004/ 🛡️ Need patching support? https://www.mydbops.com/contact #PostgreSQL #CyberSecurity #Mydbops https://t.co/yLVN5vCnnW

    Post summary

    The tweet announces a critical RCE vulnerability in PostgreSQL 14–18, provides specific patch versions and an official advisory link, without mentioning any PoC, exploit code or active exploitation.

    1001067
    467 followersView on X
  • Autumn Good@autumn_good_35
    Patch

    『This release fixes 5 security vulnerabilities and over 65 bugs reported over the last several months.』 CVE-2026-2003 CVE-2026-2004 CVE-2026-2005 CVE-2026-2006 CVE-2026-2007 PostgreSQL: PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 Released! https://www.postgresql.org/about/news/postgresql-182-178-1612-1516-and-1421-released-3235/

    Post summary

    This announcement describes the PostgreSQL 18.2 (and other) release, highlighting that it fixes five CVEs, indicating a patch update.

    00020372
    6.7K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Urgent: SUSE patch day for #PostgreSQL 18! 🛡️ Update 2026-0881-1 fixes 5 CVEs including HIGH-severity RCE flaws (CVE-2026-2004, CVE-2026-2005, CVE-2026-2006). Read more: 👉 https://tinyurl.com/uvp2en7r #openSUSE https://t.co/Bnc4yJWK3m

    Post summary

    SUSE issued patch 2026-0881-1 to fix five CVEs, including three high-severity RCE bugs in PostgreSQL 18.

    0001042
    1.3K followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Patch

    PostgreSQL、5つの重大な脆弱性を修正(CVE-2026-2004,CVE-2026-2005,CVE-2026-2006,CVE-2026-2007,CVE-2026-2003) https://rocket-boys.co.jp/security-measures-lab/postgresql-fixes-five-critical-vulnerabilities-cve-2026-2003-cve-2026-2004-cve-2026-2005-cve-2026-2006-cve-2026-2007/ #セキュリティ対策Lab #セキュリティ #Security #CybersecurityNews

    Post summary

    PostgreSQL has released patches for five critical vulnerabilities (CVE‑2026‑2003 through CVE‑2026‑2007), but no PoC, exploit, or active exploitation details are included.

    00010126
    312 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-2004: HIGH] Critical security flaw in PostgreSQL intarray extension allows execution of arbitrary code. Ensure updating to versions PostgreSQL 18.2, 17.8, 16.12, 15.16, or 14.21 to patch vulnerability.#cve,CVE-2026-2004,#cybersecurity https://cvefind.com/CVE-2026-2004

    Post summary

    The tweet alerts users to CVE‑2026‑2004, a critical RCE in PostgreSQL's intarray extension, and urges them to update to specific patched versions to remediate the issue.

    1000064
    583 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2004 Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object creator to execute arbitrary code as the operating … https://www.cve.org/CVERecord?id=CVE-2026-2004

    Post summary

    CVE-2026-2004 exposes a PostgreSQL intarray extension flaw where lack of input‑type validation lets an object creator run arbitrary code. The announcement highlights the technical details of the vulnerability but does not mention exploitation or remediation.

    00010275
    56.5K followersView on X
  • ThreatCluster@threatcluster
    Patch

    PostgreSQL 16 and 18 critical flaws patched on Mar 12 2026, including CVE-2026-2004, -2005, -2006 (CVSS 8.8) enabling code execution. openSUSE and SLE admins should update now. https://threatcluster.io/cluster/critical-vulnerabilities-in-postgresql-18-and-16-require-imm-7cdea9aa

    Post summary

    PostgreSQL 16 and 18 suffered critical flaws (CVE-2026-2004, -2005, -2006) patched on March 12, 2026; administrators are urged to apply the latest updates to mitigate code‑execution risks.

    0000037
    100 followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Critical security advisory for the fediverse: RLSA-2026:3887 patches three RCE vulnerabilities (CVE-2026-2004, CVE-2026-2005, CVE-2026-2006) in PostgreSQL 16 on #Rocky Linux 10. Read more: 👉 https://tinyurl.com/jaamsfek #Security https://t.co/QUEJi6goHf

    Post summary

    An advisory (RLSA-2026:3887) was released for PostgreSQL 16 on Rocky Linux 10, addressing three RCE CVEs (2026‑2004 to 2026‑2006) with patches available.

    0000071
    1.3K followersView on X
  • サイバーセキュリティニュース-JP@cybersecnews_jp
    Patch

    PostgreSQL、5つの重大な脆弱性を修正(CVE-2026-2004,CVE-2026-2005,CVE-2026-2006,CVE-2026-2007,CVE-2026-2003) https://rocket-boys.co.jp/security-measures-lab/postgresql-fixes-five-critical-vulnerabilities-cve-2026-2003-cve-2026-2004-cve-2026-2005-cve-2026-2006-cve-2026-2007/

    Post summary

    PostgreSQL has released patches for five critical CVEs, as announced in a security advisory linked in the post.

    0000034
    44 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    A `PostgreSQL` `intarray` extension vulnerability (UBUNTU-CVE-2026-2004) allows an object creator to execute arbitrary code as the database OS user. Upgrade `PostgreSQL` to a patched version. #PostgreSQL #DatabaseSecurity #CVE https://www.pulsepatch.io/posts/ubuntu-cve-2026-2004-postgresql-intarray-rce

    Post summary

    The post reports a PostgreSQL intarray extension vulnerability that allows arbitrary code execution and urges users to upgrade to the patched version, providing a link for more details.

    0000040
    1 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-2004 - High Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object creator to execute arbitrary code as the operating system user running the ... https://www.thehackerwire.com/vulnerability/CVE-2026-2004/ https://t.co/jyl28mddj6

    Post summary

    A new high‑severity vulnerability, CVE‑2026‑2004, is disclosed in PostgreSQL’s intarray extension where missing input type validation permits arbitrary code execution as the operating system user. No PoC, exploit, or patch details are provided.

    0000062
    112 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppostgresqlpostgresql---

Explore more