{"id":"CVE-2026-14672","year":2026,"sequence":14672,"component":"core server","score":5.3,"cvss_version":"3.0","vector":"AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","first_published":"2026-08-13","source_url":"https://www.postgresql.org/support/security/CVE-2026-14672/","facts":{"affected":{"16":"16","17":"17","18":"18"},"affected_ranges":[{"from":"16","until":"16.15"},{"from":"17","until":"17.11"},{"from":"18","until":"18.6"}],"cna_url":"https://cveawg.mitre.org/api/cve/CVE-2026-14672","component":"core server","cvss_version":"3.0","description_en":"Observable response discrepancy in PostgreSQL SCRAM authentication allows an unauthenticated user to test the existence of a user via observing the SCRAM iteration count. This requires the probed user to have a non-default scram_iterations count, because the authentication challenge for a nonexistent user reports the default scram_iterations. Within major versions 16-18, minor versions before PostgreSQL 18.6, 17.11, and 16.15 are affected. Versions before PostgreSQL 16 are unaffected.","first_published":"2026-08-13","fixed":{"16":"16.15","17":"17.11","18":"18.6"},"id":"CVE-2026-14672","introduced":{},"published":{"16":"2026-08-13","17":"2026-08-13","18":"2026-08-13"},"score":5.3,"title":"PostgreSQL observable response discrepancy with non-default scram_iterations provides user existence oracle","url":"https://www.postgresql.org/support/security/CVE-2026-14672/","vector":"AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"},"reviewed_hash":"6a65a7884245936f6adaef8709d290d460e999dfce1ad78734fa7c9a324ed325","source_hash":"965b9e2323feab543f3cbeb74c418c3a5b43cbefc6594d2862ff0d24dcf8e6a2","text":{"locale":"zh-Hans","title":"PostgreSQL 非默认 scram_iterations 会通过响应差异暴露用户是否存在","description":"PostgreSQL 非默认 scram_iterations 会通过响应差异暴露用户是否存在","details":"PostgreSQL SCRAM 身份认证存在可观察的响应差异，未认证用户可根据 SCRAM 迭代次数判断某个用户是否存在。 只有被探测用户使用非默认 scram_iterations 时才可利用，因为对不存在用户返回的认证挑战会报告默认迭代次数。 在主版本 16 至 18 中，PostgreSQL 18.6、17.11 和 16.15 之前的小版本受此问题影响； PostgreSQL 16 之前的版本不受影响。","format":"markdown","provenance":{"identity":"immutable_cve_code","sources":[{"observed_at":"2026-10-03 12:08:35.169032+08","raw":{"component":"core server","cve":"2026-14672","cvenumber":202614672,"description":"PostgreSQL 非默认 scram_iterations 会通过响应差异暴露用户是否存在","details":"PostgreSQL SCRAM 身份认证存在可观察的响应差异，未认证用户可根据 SCRAM 迭代次数判断某个用户是否存在。 只有被探测用户使用非默认 scram_iterations 时才可利用，因为对不存在用户返回的认证挑战会报告默认迭代次数。 在主版本 16 至 18 中，PostgreSQL 18.6、17.11 和 16.15 之前的小版本受此问题影响； PostgreSQL 16 之前的版本不受影响。","detailslink":"","id":96,"legacyscore":"","newspost_id":3365,"public":true,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"},"source":"center","source_id":96,"source_table_sha256":"b57ee28b2263464208af0ccf7512b31f0c1ab7140d12dda09a0c87de341f1372"},{"observed_at":"2026-10-03 12:08:55.967155+08","raw":{"component":"core server","cve":"2026-14672","cvenumber":202614672,"description":"PostgreSQL 非默认 scram_iterations 会通过响应差异暴露用户是否存在","details":"PostgreSQL SCRAM 身份认证存在可观察的响应差异，未认证用户可根据 SCRAM 迭代次数判断某个用户是否存在。 只有被探测用户使用非默认 scram_iterations 时才可利用，因为对不存在用户返回的认证挑战会报告默认迭代次数。 在主版本 16 至 18 中，PostgreSQL 18.6、17.11 和 16.15 之前的小版本受此问题影响； PostgreSQL 16 之前的版本不受影响。","detailslink":"","id":96,"legacyscore":"","newspost_id":3365,"public":true,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"},"source":"pgweb","source_id":96,"source_table_sha256":"b57ee28b2263464208af0ccf7512b31f0c1ab7140d12dda09a0c87de341f1372"}]},"text_hash":"c82672c5aa09c46eb04c3169d8c58689ac4ffbef11aeec4ac15069a9249cbdeb"},"locales":["en","zh-Hans"],"fixes":[{"major":"16","fixed_version":"16.15","introduced":null,"published_date":"2026-08-13","facts":{"fixed":"16.15","introduced":null,"published":"2026-08-13"}},{"major":"17","fixed_version":"17.11","introduced":null,"published_date":"2026-08-13","facts":{"fixed":"17.11","introduced":null,"published":"2026-08-13"}},{"major":"18","fixed_version":"18.6","introduced":null,"published_date":"2026-08-13","facts":{"fixed":"18.6","introduced":null,"published":"2026-08-13"}}],"legacy":[{"source":"center","source_id":96,"observed_at":"2026-10-03 12:08:35.169032+08","raw":{"id":96,"cve":"2026-14672","public":true,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","details":"PostgreSQL SCRAM 身份认证存在可观察的响应差异，未认证用户可根据 SCRAM 迭代次数判断某个用户是否存在。 只有被探测用户使用非默认 scram_iterations 时才可利用，因为对不存在用户返回的认证挑战会报告默认迭代次数。 在主版本 16 至 18 中，PostgreSQL 18.6、17.11 和 16.15 之前的小版本受此问题影响； PostgreSQL 16 之前的版本不受影响。","component":"core server","cvenumber":202614672,"description":"PostgreSQL 非默认 scram_iterations 会通过响应差异暴露用户是否存在","detailslink":"","legacyscore":"","newspost_id":3365},"fixes":[{"source_id":397,"source_version_id":31,"major":"18","fixed_minor":6,"raw":{"id":397,"patch_id":96,"version_id":31,"fixed_minor":6},"version_raw":{"id":31,"tree":18.0,"current":true,"docsgit":"","eoldate":"2030-11-14","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":6,"firstreldate":"2025-09-25"}},{"source_id":398,"source_version_id":30,"major":"17","fixed_minor":11,"raw":{"id":398,"patch_id":96,"version_id":30,"fixed_minor":11},"version_raw":{"id":30,"tree":17.0,"current":false,"docsgit":"","eoldate":"2029-11-08","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":11,"firstreldate":"2024-09-26"}},{"source_id":399,"source_version_id":29,"major":"16","fixed_minor":15,"raw":{"id":399,"patch_id":96,"version_id":29,"fixed_minor":15},"version_raw":{"id":29,"tree":16.0,"current":false,"docsgit":"","eoldate":"2028-11-09","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":15,"firstreldate":"2023-09-14"}}]},{"source":"pgweb","source_id":96,"observed_at":"2026-10-03 12:08:55.967155+08","raw":{"id":96,"cve":"2026-14672","public":true,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","details":"PostgreSQL SCRAM 身份认证存在可观察的响应差异，未认证用户可根据 SCRAM 迭代次数判断某个用户是否存在。 只有被探测用户使用非默认 scram_iterations 时才可利用，因为对不存在用户返回的认证挑战会报告默认迭代次数。 在主版本 16 至 18 中，PostgreSQL 18.6、17.11 和 16.15 之前的小版本受此问题影响； PostgreSQL 16 之前的版本不受影响。","component":"core server","cvenumber":202614672,"description":"PostgreSQL 非默认 scram_iterations 会通过响应差异暴露用户是否存在","detailslink":"","legacyscore":"","newspost_id":3365},"fixes":[{"source_id":397,"source_version_id":31,"major":"18","fixed_minor":6,"raw":{"id":397,"patch_id":96,"version_id":31,"fixed_minor":6},"version_raw":{"id":31,"tree":18.0,"current":true,"docsgit":"","eoldate":"2030-11-14","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":6,"firstreldate":"2025-09-25"}},{"source_id":398,"source_version_id":30,"major":"17","fixed_minor":11,"raw":{"id":398,"patch_id":96,"version_id":30,"fixed_minor":11},"version_raw":{"id":30,"tree":17.0,"current":false,"docsgit":"","eoldate":"2029-11-08","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":11,"firstreldate":"2024-09-26"}},{"source_id":399,"source_version_id":29,"major":"16","fixed_minor":15,"raw":{"id":399,"patch_id":96,"version_id":29,"fixed_minor":15},"version_raw":{"id":29,"tree":16.0,"current":false,"docsgit":"","eoldate":"2028-11-09","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":15,"firstreldate":"2023-09-14"}}]}]}
