CVE-2026-6475Disclosure(postgresql / postgresql)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-61

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • postgresql

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-05-14); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
postgresql

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-14: 1Mentions · 2026-05-21: 1Technical Details · 2026-05-14: 105-1405-21
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-141
Disclosure1
2026-05-211
General1
Full discourse2 posts
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos PostgreSQL ❗ CVE-2026-6477 ❗ CVE-2026-6475 ❗ CVE-2026-6473 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-postgresql-2/ https://t.co/yHbC0kfr1p

    Post summary

    The tweet lists three PostgreSQL CVEs and directs readers to external links for more information, but contains no PoC, exploit, or patch details.

    00000136
    6.7K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    ⚠️ HIGH — CVE-2026-6475 Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite loc… CVSS 8.8 Full analysis → https://sec.kaitan.id/cves/CVE-2026-6475 #PostgreSQL #CyberSecurity #InfoSec

    Post summary

    The tweet announces CVE-2026-6475, describing a symlink following flaw in PostgreSQL's backup tools, mentions its high CVSS score, and provides a link to a detailed analysis.

    0000046
    90 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppostgresqlpostgresql---

Explore more