{"id":"CVE-2026-14680","year":2026,"sequence":14680,"component":"core server","score":8.8,"cvss_version":"3.0","vector":"AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","first_published":"2026-08-13","source_url":"https://www.postgresql.org/support/security/CVE-2026-14680/","facts":{"affected":{"14":"14","15":"15","16":"16","17":"17","18":"18"},"affected_ranges":[{"from":"0","until":"14.24"},{"from":"15","until":"15.19"},{"from":"16","until":"16.15"},{"from":"17","until":"17.11"},{"from":"18","until":"18.6"}],"cna_url":"https://cveawg.mitre.org/api/cve/CVE-2026-14680","component":"core server","cvss_version":"3.0","description_en":"Type confusion with PostgreSQL \"internal\" data type arguments allows any user to execute arbitrary code as the operating system user running the database, via calls to functions with that argument type. Type \"internal\" represents a class of mutually-incompatible data structures not intended for access from SQL. The system intended to prevent such function calls, but this prevention had gaps. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.","first_published":"2026-08-13","fixed":{"14":"14.24","15":"15.19","16":"16.15","17":"17.11","18":"18.6"},"id":"CVE-2026-14680","introduced":{},"published":{"14":"2026-08-13","15":"2026-08-13","16":"2026-08-13","17":"2026-08-13","18":"2026-08-13"},"score":8.8,"title":"PostgreSQL type confusion via \"internal\" arguments","url":"https://www.postgresql.org/support/security/CVE-2026-14680/","vector":"AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"reviewed_hash":"6a65a7884245936f6adaef8709d290d460e999dfce1ad78734fa7c9a324ed325","source_hash":"965b9e2323feab543f3cbeb74c418c3a5b43cbefc6594d2862ff0d24dcf8e6a2","text":{"locale":"zh-Hans","title":"PostgreSQL 可通过 internal 类型参数触发类型混淆","description":"PostgreSQL 可通过 internal 类型参数触发类型混淆","details":"PostgreSQL 的 internal 数据类型参数存在类型混淆，任何用户都可通过调用带有该参数类型的函数， 以数据库服务所使用的操作系统用户身份执行任意代码。internal 类型代表一组彼此不兼容、且不应从 SQL 直接访问的数据结构；系统原本试图阻止此类函数调用，但防护仍有缺口。PostgreSQL 18.6、17.11、16.15、 15.19 和 14.24 之前的版本受此问题影响。","format":"markdown","provenance":{"identity":"immutable_cve_code","sources":[{"observed_at":"2026-10-03 12:08:35.169032+08","raw":{"component":"core server","cve":"2026-14680","cvenumber":202614680,"description":"PostgreSQL 可通过 internal 类型参数触发类型混淆","details":"PostgreSQL 的 internal 数据类型参数存在类型混淆，任何用户都可通过调用带有该参数类型的函数， 以数据库服务所使用的操作系统用户身份执行任意代码。internal 类型代表一组彼此不兼容、且不应从 SQL 直接访问的数据结构；系统原本试图阻止此类函数调用，但防护仍有缺口。PostgreSQL 18.6、17.11、16.15、 15.19 和 14.24 之前的版本受此问题影响。","detailslink":"","id":107,"legacyscore":"","newspost_id":3365,"public":true,"vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"source":"center","source_id":107,"source_table_sha256":"b57ee28b2263464208af0ccf7512b31f0c1ab7140d12dda09a0c87de341f1372"},{"observed_at":"2026-10-03 12:08:55.967155+08","raw":{"component":"core server","cve":"2026-14680","cvenumber":202614680,"description":"PostgreSQL 可通过 internal 类型参数触发类型混淆","details":"PostgreSQL 的 internal 数据类型参数存在类型混淆，任何用户都可通过调用带有该参数类型的函数， 以数据库服务所使用的操作系统用户身份执行任意代码。internal 类型代表一组彼此不兼容、且不应从 SQL 直接访问的数据结构；系统原本试图阻止此类函数调用，但防护仍有缺口。PostgreSQL 18.6、17.11、16.15、 15.19 和 14.24 之前的版本受此问题影响。","detailslink":"","id":107,"legacyscore":"","newspost_id":3365,"public":true,"vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"source":"pgweb","source_id":107,"source_table_sha256":"b57ee28b2263464208af0ccf7512b31f0c1ab7140d12dda09a0c87de341f1372"}]},"text_hash":"e3a876dcb17a49f76f8e3baa397097db6784ea00fa6e0ccf3ef90f05c2a25bdc"},"locales":["en","zh-Hans"],"fixes":[{"major":"14","fixed_version":"14.24","introduced":null,"published_date":"2026-08-13","facts":{"fixed":"14.24","introduced":null,"published":"2026-08-13"}},{"major":"15","fixed_version":"15.19","introduced":null,"published_date":"2026-08-13","facts":{"fixed":"15.19","introduced":null,"published":"2026-08-13"}},{"major":"16","fixed_version":"16.15","introduced":null,"published_date":"2026-08-13","facts":{"fixed":"16.15","introduced":null,"published":"2026-08-13"}},{"major":"17","fixed_version":"17.11","introduced":null,"published_date":"2026-08-13","facts":{"fixed":"17.11","introduced":null,"published":"2026-08-13"}},{"major":"18","fixed_version":"18.6","introduced":null,"published_date":"2026-08-13","facts":{"fixed":"18.6","introduced":null,"published":"2026-08-13"}}],"legacy":[{"source":"center","source_id":107,"observed_at":"2026-10-03 12:08:35.169032+08","raw":{"id":107,"cve":"2026-14680","public":true,"vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","details":"PostgreSQL 的 internal 数据类型参数存在类型混淆，任何用户都可通过调用带有该参数类型的函数， 以数据库服务所使用的操作系统用户身份执行任意代码。internal 类型代表一组彼此不兼容、且不应从 SQL 直接访问的数据结构；系统原本试图阻止此类函数调用，但防护仍有缺口。PostgreSQL 18.6、17.11、16.15、 15.19 和 14.24 之前的版本受此问题影响。","component":"core server","cvenumber":202614680,"description":"PostgreSQL 可通过 internal 类型参数触发类型混淆","detailslink":"","legacyscore":"","newspost_id":3365},"fixes":[{"source_id":445,"source_version_id":31,"major":"18","fixed_minor":6,"raw":{"id":445,"patch_id":107,"version_id":31,"fixed_minor":6},"version_raw":{"id":31,"tree":18.0,"current":true,"docsgit":"","eoldate":"2030-11-14","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":6,"firstreldate":"2025-09-25"}},{"source_id":446,"source_version_id":30,"major":"17","fixed_minor":11,"raw":{"id":446,"patch_id":107,"version_id":30,"fixed_minor":11},"version_raw":{"id":30,"tree":17.0,"current":false,"docsgit":"","eoldate":"2029-11-08","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":11,"firstreldate":"2024-09-26"}},{"source_id":447,"source_version_id":29,"major":"16","fixed_minor":15,"raw":{"id":447,"patch_id":107,"version_id":29,"fixed_minor":15},"version_raw":{"id":29,"tree":16.0,"current":false,"docsgit":"","eoldate":"2028-11-09","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":15,"firstreldate":"2023-09-14"}},{"source_id":448,"source_version_id":28,"major":"15","fixed_minor":19,"raw":{"id":448,"patch_id":107,"version_id":28,"fixed_minor":19},"version_raw":{"id":28,"tree":15.0,"current":false,"docsgit":"","eoldate":"2027-11-11","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":19,"firstreldate":"2022-10-13"}},{"source_id":449,"source_version_id":27,"major":"14","fixed_minor":24,"raw":{"id":449,"patch_id":107,"version_id":27,"fixed_minor":24},"version_raw":{"id":27,"tree":14.0,"current":false,"docsgit":"","eoldate":"2026-11-12","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":24,"firstreldate":"2021-09-30"}}]},{"source":"pgweb","source_id":107,"observed_at":"2026-10-03 12:08:55.967155+08","raw":{"id":107,"cve":"2026-14680","public":true,"vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","details":"PostgreSQL 的 internal 数据类型参数存在类型混淆，任何用户都可通过调用带有该参数类型的函数， 以数据库服务所使用的操作系统用户身份执行任意代码。internal 类型代表一组彼此不兼容、且不应从 SQL 直接访问的数据结构；系统原本试图阻止此类函数调用，但防护仍有缺口。PostgreSQL 18.6、17.11、16.15、 15.19 和 14.24 之前的版本受此问题影响。","component":"core server","cvenumber":202614680,"description":"PostgreSQL 可通过 internal 类型参数触发类型混淆","detailslink":"","legacyscore":"","newspost_id":3365},"fixes":[{"source_id":445,"source_version_id":31,"major":"18","fixed_minor":6,"raw":{"id":445,"patch_id":107,"version_id":31,"fixed_minor":6},"version_raw":{"id":31,"tree":18.0,"current":true,"docsgit":"","eoldate":"2030-11-14","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":6,"firstreldate":"2025-09-25"}},{"source_id":446,"source_version_id":30,"major":"17","fixed_minor":11,"raw":{"id":446,"patch_id":107,"version_id":30,"fixed_minor":11},"version_raw":{"id":30,"tree":17.0,"current":false,"docsgit":"","eoldate":"2029-11-08","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":11,"firstreldate":"2024-09-26"}},{"source_id":447,"source_version_id":29,"major":"16","fixed_minor":15,"raw":{"id":447,"patch_id":107,"version_id":29,"fixed_minor":15},"version_raw":{"id":29,"tree":16.0,"current":false,"docsgit":"","eoldate":"2028-11-09","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":15,"firstreldate":"2023-09-14"}},{"source_id":448,"source_version_id":28,"major":"15","fixed_minor":19,"raw":{"id":448,"patch_id":107,"version_id":28,"fixed_minor":19},"version_raw":{"id":28,"tree":15.0,"current":false,"docsgit":"","eoldate":"2027-11-11","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":19,"firstreldate":"2022-10-13"}},{"source_id":449,"source_version_id":27,"major":"14","fixed_minor":24,"raw":{"id":449,"patch_id":107,"version_id":27,"fixed_minor":24},"version_raw":{"id":27,"tree":14.0,"current":false,"docsgit":"","eoldate":"2026-11-12","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":24,"firstreldate":"2021-09-30"}}]}]}
