{"id":"CVE-2026-18408","year":2026,"sequence":18408,"component":"client","score":8.8,"cvss_version":"3.0","vector":"AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","first_published":"2026-08-13","source_url":"https://www.postgresql.org/support/security/CVE-2026-18408/","facts":{"affected":{"14":"14","15":"15","16":"16","17":"17","18":"18"},"affected_ranges":[{"from":"0","until":"14.24"},{"from":"15","until":"15.19"},{"from":"16","until":"16.15"},{"from":"17","until":"17.11"},{"from":"18","until":"18.6"}],"cna_url":"https://cveawg.mitre.org/api/cve/CVE-2026-18408","component":"client","cvss_version":"3.0","description_en":"Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql \\restrict meta-command input expansion. The fix for CVE-2025-8714 introduced \\restrict and \\unrestrict to block this attack, but \\unrestrict itself was sufficient for an attack. pg_dumpall is also affected. pg_restore is affected when used to generate a plain-format dump. Non-core use of \\restrict would be affected, but we've not identified non-core use. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.","first_published":"2026-08-13","fixed":{"14":"14.24","15":"15.19","16":"16.15","17":"17.11","18":"18.6"},"id":"CVE-2026-18408","introduced":{},"published":{"14":"2026-08-13","15":"2026-08-13","16":"2026-08-13","17":"2026-08-13","18":"2026-08-13"},"score":8.8,"title":"PostgreSQL psql \\unrestrict lets superuser of pg_dump origin server execute arbitrary code in psql client","url":"https://www.postgresql.org/support/security/CVE-2026-18408/","vector":"AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},"reviewed_hash":"6a65a7884245936f6adaef8709d290d460e999dfce1ad78734fa7c9a324ed325","source_hash":"965b9e2323feab543f3cbeb74c418c3a5b43cbefc6594d2862ff0d24dcf8e6a2","text":{"locale":"zh-Hans","title":"PostgreSQL psql 的 \\unrestrict 可让来源服务器超级用户在客户端执行任意代码","description":"PostgreSQL psql 的 \\unrestrict 可让来源服务器超级用户在客户端执行任意代码","details":"PostgreSQL pg_dump 纳入不可信数据时，恶意的来源服务器超级用户可利用 psql \\restrict 元命令的输入展开， 注入在恢复时执行的任意代码，并以运行 psql 恢复转储的客户端操作系统账户身份执行。针对 CVE-2025-8714 的修复引入了 \\restrict 与 \\unrestrict 来阻止此类攻击，但 \\unrestrict 本身已经足以完成攻击。 pg_dumpall 同样受影响；使用 pg_restore 生成纯文本格式转储时也会受影响。非核心组件若使用 \\restrict 也可能受影响，但目前尚未发现此类用法。PostgreSQL 18.6、17.11、16.15、15.19 和 14.24 之前的版本受此问题影响。","format":"markdown","provenance":{"identity":"immutable_cve_code","sources":[{"observed_at":"2026-10-03 12:08:35.169032+08","raw":{"component":"client","cve":"2026-18408","cvenumber":202618408,"description":"PostgreSQL psql 的 \\unrestrict 可让来源服务器超级用户在客户端执行任意代码","details":"PostgreSQL pg_dump 纳入不可信数据时，恶意的来源服务器超级用户可利用 psql \\restrict 元命令的输入展开， 注入在恢复时执行的任意代码，并以运行 psql 恢复转储的客户端操作系统账户身份执行。针对 CVE-2025-8714 的修复引入了 \\restrict 与 \\unrestrict 来阻止此类攻击，但 \\unrestrict 本身已经足以完成攻击。 pg_dumpall 同样受影响；使用 pg_restore 生成纯文本格式转储时也会受影响。非核心组件若使用 \\restrict 也可能受影响，但目前尚未发现此类用法。PostgreSQL 18.6、17.11、16.15、15.19 和 14.24 之前的版本受此问题影响。","detailslink":"","id":92,"legacyscore":"","newspost_id":3365,"public":true,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},"source":"center","source_id":92,"source_table_sha256":"b57ee28b2263464208af0ccf7512b31f0c1ab7140d12dda09a0c87de341f1372"},{"observed_at":"2026-10-03 12:08:55.967155+08","raw":{"component":"client","cve":"2026-18408","cvenumber":202618408,"description":"PostgreSQL psql 的 \\unrestrict 可让来源服务器超级用户在客户端执行任意代码","details":"PostgreSQL pg_dump 纳入不可信数据时，恶意的来源服务器超级用户可利用 psql \\restrict 元命令的输入展开， 注入在恢复时执行的任意代码，并以运行 psql 恢复转储的客户端操作系统账户身份执行。针对 CVE-2025-8714 的修复引入了 \\restrict 与 \\unrestrict 来阻止此类攻击，但 \\unrestrict 本身已经足以完成攻击。 pg_dumpall 同样受影响；使用 pg_restore 生成纯文本格式转储时也会受影响。非核心组件若使用 \\restrict 也可能受影响，但目前尚未发现此类用法。PostgreSQL 18.6、17.11、16.15、15.19 和 14.24 之前的版本受此问题影响。","detailslink":"","id":92,"legacyscore":"","newspost_id":3365,"public":true,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},"source":"pgweb","source_id":92,"source_table_sha256":"b57ee28b2263464208af0ccf7512b31f0c1ab7140d12dda09a0c87de341f1372"}]},"text_hash":"5e1299f1e244990a5de9f17295b62e86ad320dd9ba4b84b095507857acd39168"},"locales":["en","zh-Hans"],"fixes":[{"major":"14","fixed_version":"14.24","introduced":null,"published_date":"2026-08-13","facts":{"fixed":"14.24","introduced":null,"published":"2026-08-13"}},{"major":"15","fixed_version":"15.19","introduced":null,"published_date":"2026-08-13","facts":{"fixed":"15.19","introduced":null,"published":"2026-08-13"}},{"major":"16","fixed_version":"16.15","introduced":null,"published_date":"2026-08-13","facts":{"fixed":"16.15","introduced":null,"published":"2026-08-13"}},{"major":"17","fixed_version":"17.11","introduced":null,"published_date":"2026-08-13","facts":{"fixed":"17.11","introduced":null,"published":"2026-08-13"}},{"major":"18","fixed_version":"18.6","introduced":null,"published_date":"2026-08-13","facts":{"fixed":"18.6","introduced":null,"published":"2026-08-13"}}],"legacy":[{"source":"center","source_id":92,"observed_at":"2026-10-03 12:08:35.169032+08","raw":{"id":92,"cve":"2026-18408","public":true,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","details":"PostgreSQL pg_dump 纳入不可信数据时，恶意的来源服务器超级用户可利用 psql \\restrict 元命令的输入展开， 注入在恢复时执行的任意代码，并以运行 psql 恢复转储的客户端操作系统账户身份执行。针对 CVE-2025-8714 的修复引入了 \\restrict 与 \\unrestrict 来阻止此类攻击，但 \\unrestrict 本身已经足以完成攻击。 pg_dumpall 同样受影响；使用 pg_restore 生成纯文本格式转储时也会受影响。非核心组件若使用 \\restrict 也可能受影响，但目前尚未发现此类用法。PostgreSQL 18.6、17.11、16.15、15.19 和 14.24 之前的版本受此问题影响。","component":"client","cvenumber":202618408,"description":"PostgreSQL psql 的 \\unrestrict 可让来源服务器超级用户在客户端执行任意代码","detailslink":"","legacyscore":"","newspost_id":3365},"fixes":[{"source_id":377,"source_version_id":31,"major":"18","fixed_minor":6,"raw":{"id":377,"patch_id":92,"version_id":31,"fixed_minor":6},"version_raw":{"id":31,"tree":18.0,"current":true,"docsgit":"","eoldate":"2030-11-14","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":6,"firstreldate":"2025-09-25"}},{"source_id":378,"source_version_id":30,"major":"17","fixed_minor":11,"raw":{"id":378,"patch_id":92,"version_id":30,"fixed_minor":11},"version_raw":{"id":30,"tree":17.0,"current":false,"docsgit":"","eoldate":"2029-11-08","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":11,"firstreldate":"2024-09-26"}},{"source_id":379,"source_version_id":29,"major":"16","fixed_minor":15,"raw":{"id":379,"patch_id":92,"version_id":29,"fixed_minor":15},"version_raw":{"id":29,"tree":16.0,"current":false,"docsgit":"","eoldate":"2028-11-09","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":15,"firstreldate":"2023-09-14"}},{"source_id":380,"source_version_id":28,"major":"15","fixed_minor":19,"raw":{"id":380,"patch_id":92,"version_id":28,"fixed_minor":19},"version_raw":{"id":28,"tree":15.0,"current":false,"docsgit":"","eoldate":"2027-11-11","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":19,"firstreldate":"2022-10-13"}},{"source_id":381,"source_version_id":27,"major":"14","fixed_minor":24,"raw":{"id":381,"patch_id":92,"version_id":27,"fixed_minor":24},"version_raw":{"id":27,"tree":14.0,"current":false,"docsgit":"","eoldate":"2026-11-12","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":24,"firstreldate":"2021-09-30"}}]},{"source":"pgweb","source_id":92,"observed_at":"2026-10-03 12:08:55.967155+08","raw":{"id":92,"cve":"2026-18408","public":true,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","details":"PostgreSQL pg_dump 纳入不可信数据时，恶意的来源服务器超级用户可利用 psql \\restrict 元命令的输入展开， 注入在恢复时执行的任意代码，并以运行 psql 恢复转储的客户端操作系统账户身份执行。针对 CVE-2025-8714 的修复引入了 \\restrict 与 \\unrestrict 来阻止此类攻击，但 \\unrestrict 本身已经足以完成攻击。 pg_dumpall 同样受影响；使用 pg_restore 生成纯文本格式转储时也会受影响。非核心组件若使用 \\restrict 也可能受影响，但目前尚未发现此类用法。PostgreSQL 18.6、17.11、16.15、15.19 和 14.24 之前的版本受此问题影响。","component":"client","cvenumber":202618408,"description":"PostgreSQL psql 的 \\unrestrict 可让来源服务器超级用户在客户端执行任意代码","detailslink":"","legacyscore":"","newspost_id":3365},"fixes":[{"source_id":377,"source_version_id":31,"major":"18","fixed_minor":6,"raw":{"id":377,"patch_id":92,"version_id":31,"fixed_minor":6},"version_raw":{"id":31,"tree":18.0,"current":true,"docsgit":"","eoldate":"2030-11-14","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":6,"firstreldate":"2025-09-25"}},{"source_id":378,"source_version_id":30,"major":"17","fixed_minor":11,"raw":{"id":378,"patch_id":92,"version_id":30,"fixed_minor":11},"version_raw":{"id":30,"tree":17.0,"current":false,"docsgit":"","eoldate":"2029-11-08","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":11,"firstreldate":"2024-09-26"}},{"source_id":379,"source_version_id":29,"major":"16","fixed_minor":15,"raw":{"id":379,"patch_id":92,"version_id":29,"fixed_minor":15},"version_raw":{"id":29,"tree":16.0,"current":false,"docsgit":"","eoldate":"2028-11-09","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":15,"firstreldate":"2023-09-14"}},{"source_id":380,"source_version_id":28,"major":"15","fixed_minor":19,"raw":{"id":380,"patch_id":92,"version_id":28,"fixed_minor":19},"version_raw":{"id":28,"tree":15.0,"current":false,"docsgit":"","eoldate":"2027-11-11","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":19,"firstreldate":"2022-10-13"}},{"source_id":381,"source_version_id":27,"major":"14","fixed_minor":24,"raw":{"id":381,"patch_id":92,"version_id":27,"fixed_minor":24},"version_raw":{"id":27,"tree":14.0,"current":false,"docsgit":"","eoldate":"2026-11-12","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":24,"firstreldate":"2021-09-30"}}]}]}
