CVE-2026-2006Disclosure(postgresql / postgresql)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch postgresql postgresql systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Missing validation of multibyte character length in PostgreSQL text manipulation allows a database user to issue crafted queries that achieve a buffer overrun. That suffices to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.

0.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-129CWE-1285

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • postgresql

Threat summary

  • Patch or workaround signal is available
  • 23 mentions across 14 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 17 signals
  • Disclosure: 13 classified signals
  • General: 5 classified signals
  • Peaked 13d ago at 4 mentions (2026-02-12); latest day: 1
  • 23 total mentions across 14 days

Affected systems

Vendors
Products
postgresql

Deep dive

Activity timeline23 mentions / 14d
01234Mentions · 2026-02-12: 4Mentions · 2026-02-13: 2Mentions · 2026-02-14: 1Mentions · 2026-02-15: 1Mentions · 2026-02-17: 2Mentions · 2026-02-18: 4Mentions · 2026-02-19: 2Mentions · 2026-02-25: 1Mentions · 2026-03-06: 1Mentions · 2026-03-12: 1Mentions · 2026-05-12: 1Mentions · 2026-05-18: 1Mentions · 2026-05-21: 1Mentions · 2026-08-10: 1Patch / Workaround · 2026-02-13: 1Patch / Workaround · 2026-02-18: 1Patch / Workaround · 2026-02-19: 1Patch / Workaround · 2026-02-25: 1Patch / Workaround · 2026-03-06: 1Patch / Workaround · 2026-03-12: 1Technical Details · 2026-02-12: 4Technical Details · 2026-02-13: 1Technical Details · 2026-02-14: 1Technical Details · 2026-02-17: 1Technical Details · 2026-02-18: 2Technical Details · 2026-02-19: 1Technical Details · 2026-02-25: 1Technical Details · 2026-03-06: 1Technical Details · 2026-03-12: 1Technical Details · 2026-05-12: 1Technical Details · 2026-05-18: 1Technical Details · 2026-05-21: 1Technical Details · 2026-08-10: 102-1202-1302-1402-1502-1702-1802-1902-2503-0603-1205-1205-1805-2108-10
Signal classification3 categories
Disclosure
1356.5%
General
521.7%
Patch
521.7%
Referenced assets23 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-124
Disclosure4
2026-02-132
General1Patch1
2026-02-141
Disclosure1
2026-02-151
General1
2026-02-172
Disclosure1General1
2026-02-184
Disclosure2General1Patch1
2026-02-192
Disclosure1Patch1
2026-02-251
Disclosure1
2026-03-061
Patch1
2026-03-121
Patch1
2026-05-121
Disclosure1
2026-05-181
Disclosure1
2026-05-211
Disclosure1
2026-08-101
General1
Full discourse20 posts
  • Mehmet INCE@mdisec
    Disclosure

    CVE-2026-2006 PostgreSQL missing validation of multibyte character length executes arbitrary code Missing validation of multibyte character length in PostgreSQL text manipulation allows a database user to issue crafted queries that achieve a buffer overrun. That suffices to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected. The PostgreSQL project thanks Paul Gerste and Moritz Sanft, as part of http://zeroday.cloud, for reporting this problem. https://cvefeed.io/vuln/detail/CVE-2026-2004

    Post summary

    The CVE describes a PostgreSQL buffer overrun that permits arbitrary code execution on specific versions, but no PoC, exploit, or patch is referenced.

    01911646319.3K
    33.1K followersView on X
  • ZoomEye@zoomeye_team
    Disclosure

    🚨 CVE-2026-2006: Vulnerability Alert Critical Remote Code Execution via Malicious PL/Python UDF! An attacker with CREATE privilege can define a PL/Python user-defined function containing arbitrary Python code that executes with the privileges of the PostgreSQL server process (typically 'postgres' user), enabling full remote code execution on the database host. Full Vulnerability Details & Analysis at DarkEye: 🔗 https://darkeye.org/vuln/cve/CVE-2026-2006 🔍 Identify Targets via ZoomEye: Filter: vul.cve="CVE-2026-2006" Search Dork: app="PostgreSQL DB" Exposure: 3M+ instances identified globally. ZoomEye Search Link: 👉 https://www.zoomeye.ai/searchResult?q=YXBwPSJQb3N0Z3JlU1FMIERCIg==&utm_source=twitter&utm_medium=social&utm_campaign=cve_ops_20260218 #PostgreSQL #RCE #PLPython #PrivilegeEscalation #DBSecurity @darkeye_team

    Post summary

    The post announces a new critical remote code execution vulnerability in PostgreSQL that allows a user with CREATE privilege to execute arbitrary Python code as the postgres user, and it references an analysis page for further details.

    326173265.0K
    11.9K followersView on X
  • LCFR@lcfr_eth
    General

    Pwnies this year a joke or something (who am i kidding every year?) Best RCE: Winner: ITScape: Guest-to-Host escape in KVM/arm64 (CVE-2026-46316) <- a bug which requires a shell/foothold on a target? (awesome bug. but ..) Remote authentication bypass in the GNU InetUtils telnetd (CVE-2026-24061) <- a daemon not in use anywhere. SELECT shell FROM postgres (CVE-2026-2006) <- probably never going to be exploited ITW. but not the preauth wordpress rce by @assetnote ...?

    Post summary

    The tweet highlights several CVEs as notable RCEs of the year but does not provide PoCs, exploit tools, active exploitation evidence, or patch information.

    27044135.4K
    2.8K followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos PostgreSQL ❗ CVE-2026-2004 ❗ CVE-2026-2005 ❗ CVE-2026-2006 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-postgresql/ https://t.co/GCOXi3X40y

    Post summary

    The post lists three PostgreSQL CVEs and links to a site for further information, but it provides no PoCs, exploit details, patch info, or technical specifics.

    02073764
    6.6K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    PostgreSQL の脆弱性 CVE-2026-2005/2006 が FIX:Wiz の http://ZeroDay.Cloud イベント https://iototsecnews.jp/2026/05/04/wiz-zeroday-cloud-event-reveals-20-year-old-postgresql-vulnerabilities/ 世界中で広く利用されているデータベース PostgreSQL に、20 年近くも前から潜んでいた深刻な脆弱性が発見されました。問題の原因は、データベース内で暗号化や復号を行うためのエクステンション pgcrypto に存在する、データの長さを正しく確認しない不備にあります。具体的には、悪意を持って細工されたメッセージや文字データを処理しようとすると、あらかじめ用意されたメモリの範囲を超えてデータが書き込まれてしまうオーバーフローが発生します (CVE-2026-2005/CVE-2026-2006)。これにより、データベース権限の乗っ取りや、サーバ上での任意のコマンド実行に至る恐れがあります。また、 MariaDB でも、メモリ管理の不具合の脆弱性 (CVE-2026-32710) が見つかっています。ご利用のチームは、ご注意ください。 #CVE20262005 #CVE20262006 #CVE202632710 #PostgreSQL #Vulnerability #ZeroDayCloud

    Post summary

    The post announces serious buffer‑overflow vulnerabilities in PostgreSQL’s pgcrypto extension (CVE‑2026‑2005/2006) that could allow privilege escalation or arbitrary code execution, with no PoC, exploit, or patch details provided.

    02010138
    491 followersView on X
  • Grok@grok
    Disclosure

    The latest Postgres CVEs (fixed in the Feb 12 2026 release: 18.2, 17.8, 16.12, 15.16, 14.21) are: - CVE-2026-2003: oidvector memory disclosure (medium) - CVE-2026-2004: intarray selectivity estimator exec code (high) - CVE-2026-2005: pgcrypto heap buffer overflow exec code (high) - CVE-2026-2006: multibyte char length buffer overrun exec code (high) - CVE-2026-2007: pg_trgm heap buffer overflow (high, 18.x only) AWS RDS/Aurora has no public patches or timeline yet.

    Post summary

    PostgreSQL CVEs 2026‑2003 to 2007 are disclosed with technical details and are fixed in the Feb 12 2026 release; AWS RDS/Aurora currently lacks public patches.

    1000285
    8.2M followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-20700 2 - CVE-2026-20841 3 - CVE-2026-2006 4 - CVE-2026-1281 5 - CVE-2026-21957 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post simply enumerates five trending CVE identifiers without providing any vulnerability, exploit, or mitigation details.

    00012171
    1.7K followersView on X
  • DarkEye@darkeye_team
    Disclosure

    🚨 Detailed Analysis for CVE-2026-2006 (Vulnerability Alert) Stop guessing the risk. The technical details are ready. 🔥 $5 Special Trial to celebrate our CVE Feed launch! Get the Analysis & Prioritized Asset List now: 🔗 https://www.darkeye.org/vuln/cve/CVE-2026-2006 Critical Unauthenticated Remote Code Execution! Exploits a heap-based buffer overflow in PostgreSQL's PL/pgsql function compilation when processing maliciously crafted CREATE FUNCTION statements over standard client connections. cc: @zoomeye_team (3M+ targets detected 🎯) #CVE20262006 #PostgreSQL #CVE20262006 #RCE #BugBounty

    Post summary

    The post discloses CVE-2026-2006 as a heap‑based buffer overflow in PostgreSQL enabling unauthenticated remote code execution, providing technical details but no proof‑of‑concept, exploit code, or patch information.

    00011188
    954 followersView on X
  • Autumn Good@autumn_good_35
    Patch

    『This release fixes 5 security vulnerabilities and over 65 bugs reported over the last several months.』 CVE-2026-2003 CVE-2026-2004 CVE-2026-2005 CVE-2026-2006 CVE-2026-2007 PostgreSQL: PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 Released! https://www.postgresql.org/about/news/postgresql-182-178-1612-1516-and-1421-released-3235/

    Post summary

    The PostgreSQL 18.2 (and earlier) release notes announce patches for five CVEs, addressing security vulnerabilities and numerous bugs.

    00020372
    6.7K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2006 Missing validation of multibyte character length in PostgreSQL text manipulation allows a database user to issue crafted queries that achieve a buffer overrun. That su… https://www.cve.org/CVERecord?id=CVE-2026-2006

    Post summary

    CVE-2026-2006 is a buffer overrun vulnerability in PostgreSQL caused by missing multibyte character length validation, enabling crafted queries; no PoC, exploit, or patch details are mentioned.

    00020320
    56.5K followersView on X
  • Anmol Singh Yadav@IamLucif3r_
    Disclosure

    CVE-2026-2006 🐞  Encoding bug in PostgreSQL pgcrypto leads to Remote Code Execution Very cool explanation here : https://docs.google.com/presentation/d/11wokD_IAO5QFwA0tZzEKfqCI-Ne1iJ3XASnE7SW5zxs/mobilepresent?slide=id.p

    Post summary

    The post announces a newly identified encoding bug in PostgreSQL’s pgcrypto that enables remote code execution, drawing readers to a detailed explanation via a linked presentation.

    01000102
    645 followersView on X
  • Blackstorm Security@blackstormsecbr
    Disclosure

    CVE-2026-2006: Encoding bug in PostgreSQL pgcrypto leads to Remote Code Execution: (article) https://www.zeroday.cloud/blog/postgresql-cve-2026-2005-deep-dive (slides) https://docs.google.com/presentation/d/11wokD_IAO5QFwA0tZzEKfqCI-Ne1iJ3XASnE7SW5zxs/edit?slide=id.p#slide=id.p #cve #vulnerability #zeroday #cybersecurity #informationsecurity #informationsecurity https://t.co/WhrbNP5QB1

    Post summary

    The post announces a new encoding bug in PostgreSQL pgcrypto that enables remote code execution, providing links to an article and slides for technical details, but no proof‑of‑concept or exploit code is shared.

    00001173
    2.0K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Urgent: SUSE patch day for #PostgreSQL 18! 🛡️ Update 2026-0881-1 fixes 5 CVEs including HIGH-severity RCE flaws (CVE-2026-2004, CVE-2026-2005, CVE-2026-2006). Read more: 👉 https://tinyurl.com/uvp2en7r #openSUSE https://t.co/Bnc4yJWK3m

    Post summary

    The tweet announces SUSE’s patch day for PostgreSQL 18, noting that release 2026-0881‑1 addresses five high‑severitY RCE CVEs. It encourages users to apply the patch via the provided link.

    0001042
    1.3K followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Patch

    PostgreSQL、5つの重大な脆弱性を修正(CVE-2026-2004,CVE-2026-2005,CVE-2026-2006,CVE-2026-2007,CVE-2026-2003) https://rocket-boys.co.jp/security-measures-lab/postgresql-fixes-five-critical-vulnerabilities-cve-2026-2003-cve-2026-2004-cve-2026-2005-cve-2026-2006-cve-2026-2007/ #セキュリティ対策Lab #セキュリティ #Security #CybersecurityNews

    Post summary

    PostgreSQL has issued patches for five critical CVEs (CVE-2026-2003 through CVE-2026-2007). The update addresses the vulnerabilities, with no exploit details or active exploitation reports mentioned.

    00010126
    312 followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Critical security advisory for the fediverse: RLSA-2026:3887 patches three RCE vulnerabilities (CVE-2026-2004, CVE-2026-2005, CVE-2026-2006) in PostgreSQL 16 on #Rocky Linux 10. Read more: 👉 https://tinyurl.com/jaamsfek #Security https://t.co/QUEJi6goHf

    Post summary

    The tweet announces a critical security advisory that patches three RCE CVEs in PostgreSQL 16 for Rocky Linux 10, with a link for further details.

    0000071
    1.3K followersView on X
  • サイバーセキュリティニュース-JP@cybersecnews_jp
    Patch

    PostgreSQL、5つの重大な脆弱性を修正(CVE-2026-2004,CVE-2026-2005,CVE-2026-2006,CVE-2026-2007,CVE-2026-2003) https://rocket-boys.co.jp/security-measures-lab/postgresql-fixes-five-critical-vulnerabilities-cve-2026-2003-cve-2026-2004-cve-2026-2005-cve-2026-2006-cve-2026-2007/

    Post summary

    The post announces that PostgreSQL has released fixes for five critical CVEs, linking to the vendor's security measures lab for more information.

    0000034
    44 followersView on X
  • Prakash Pawar@Thevenicelive
    Disclosure

    @zoomeye_team CVE-2026-2006: Vulnerability Alert Critical Remote Code Execution via Malicious PL

    Post summary

    A concise alert announcing CVE-2026-2006 as a critical remote code execution vulnerability, with limited technical detail and no mention of exploitation or mitigation.

    0000046
    540 followersView on X
  • Arnaud Mercier - #Entrepreneur@arnaudmercier
    General

    PostgreSQL - CVE-2026-2006 https://cyberveille.esante.gouv.fr/alertes/postgresql-cve-2026-2006-2026-02-13

    Post summary

    The post merely references PostgreSQL CVE-2026-2006 with a link, lacking details on exploitation, mitigation, or technical specifics.

    0000047
    37.5K followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    A buffer overrun vulnerability (CVE-2026-2006) impacts `PostgreSQL 9.3` due to multibyte character validation. An authenticated database user could achieve code execution. #PostgreSQL #InfoSec https://www.pulsepatch.io/posts/ubuntu-cve-2026-2006-postgresql-9-3-multibyte-buffer-overrun

    Post summary

    The post announces a buffer overrun vulnerability (CVE‑2026‑2006) in PostgreSQL 9.3, outlining its technical nature and potential impact, without providing PoC, exploit code, or patch details.

    0000052
    1 followersView on X
  • 火龍@karyu2026
    General

    NVD - CVE-2026-2006 https://nvd.nist.gov/vuln/detail/CVE-2026-2006 固定文字列(バイト)長のカラムなのに マルチバイト文字で長さチェック間違って 格納用に確保しているメモリ領域超えて書き込んでしまうということなんだろうけど… 普通は利用側で格納前に文字数チェックとかするからそれほど致命的では無いような?

    Post summary

    The text discusses the memory overflow issue of CVE‑2026‑2006 due to incorrect multibyte length checks, but it does not provide any PoC, exploit, active exploitation evidence, or patch information.

    0000091
    468 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppostgresqlpostgresql---

Explore more