{"id":"CVE-2026-6471","year":2026,"sequence":6471,"component":"core server","score":7.2,"cvss_version":"3.0","vector":"AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","first_published":"2026-08-13","source_url":"https://www.postgresql.org/support/security/CVE-2026-6471/","facts":{"affected":{"14":"14","15":"15","16":"16","17":"17","18":"18"},"affected_ranges":[{"from":"0","until":"14.24"},{"from":"15","until":"15.19"},{"from":"16","until":"16.15"},{"from":"17","until":"17.11"},{"from":"18","until":"18.6"}],"cna_url":"https://cveawg.mitre.org/api/cve/CVE-2026-6471","component":"core server","cvss_version":"3.0","description_en":"Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating system account running the server, via the choice of logical decoding plugin. This in turn runs arbitrary code as that account. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.","first_published":"2026-08-13","fixed":{"14":"14.24","15":"15.19","16":"16.15","17":"17.11","18":"18.6"},"id":"CVE-2026-6471","introduced":{},"published":{"14":"2026-08-13","15":"2026-08-13","16":"2026-08-13","17":"2026-08-13","18":"2026-08-13"},"score":7.2,"title":"PostgreSQL logical decoding can dlopen arbitrary file","url":"https://www.postgresql.org/support/security/CVE-2026-6471/","vector":"AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"},"reviewed_hash":"6a65a7884245936f6adaef8709d290d460e999dfce1ad78734fa7c9a324ed325","source_hash":"965b9e2323feab543f3cbeb74c418c3a5b43cbefc6594d2862ff0d24dcf8e6a2","text":{"locale":"zh-Hans","title":"PostgreSQL 逻辑解码可通过 dlopen 加载任意文件","description":"PostgreSQL 逻辑解码可通过 dlopen 加载任意文件","details":"PostgreSQL 逻辑解码缺少授权检查，持有 REPLICATION 权限的非超级用户可通过选择逻辑解码插件， 让服务器使用 dlopen 加载数据库服务操作系统账户可见的任意文件，进而以该账户身份执行任意代码。 PostgreSQL 18.6、17.11、16.15、15.19 和 14.24 之前的版本受此问题影响。","format":"markdown","provenance":{"identity":"immutable_cve_code","sources":[{"observed_at":"2026-10-03 12:08:35.169032+08","raw":{"component":"core server","cve":"2026-6471","cvenumber":202606471,"description":"PostgreSQL 逻辑解码可通过 dlopen 加载任意文件","details":"PostgreSQL 逻辑解码缺少授权检查，持有 REPLICATION 权限的非超级用户可通过选择逻辑解码插件， 让服务器使用 dlopen 加载数据库服务操作系统账户可见的任意文件，进而以该账户身份执行任意代码。 PostgreSQL 18.6、17.11、16.15、15.19 和 14.24 之前的版本受此问题影响。","detailslink":"","id":87,"legacyscore":"","newspost_id":3365,"public":true,"vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"},"source":"center","source_id":87,"source_table_sha256":"b57ee28b2263464208af0ccf7512b31f0c1ab7140d12dda09a0c87de341f1372"},{"observed_at":"2026-10-03 12:08:55.967155+08","raw":{"component":"core server","cve":"2026-6471","cvenumber":202606471,"description":"PostgreSQL 逻辑解码可通过 dlopen 加载任意文件","details":"PostgreSQL 逻辑解码缺少授权检查，持有 REPLICATION 权限的非超级用户可通过选择逻辑解码插件， 让服务器使用 dlopen 加载数据库服务操作系统账户可见的任意文件，进而以该账户身份执行任意代码。 PostgreSQL 18.6、17.11、16.15、15.19 和 14.24 之前的版本受此问题影响。","detailslink":"","id":87,"legacyscore":"","newspost_id":3365,"public":true,"vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"},"source":"pgweb","source_id":87,"source_table_sha256":"b57ee28b2263464208af0ccf7512b31f0c1ab7140d12dda09a0c87de341f1372"}]},"text_hash":"897018052ab52292375e97e5d8a528e04bd1eb1f208c09222569c8b3c3527dfd"},"locales":["en","zh-Hans"],"fixes":[{"major":"14","fixed_version":"14.24","introduced":null,"published_date":"2026-08-13","facts":{"fixed":"14.24","introduced":null,"published":"2026-08-13"}},{"major":"15","fixed_version":"15.19","introduced":null,"published_date":"2026-08-13","facts":{"fixed":"15.19","introduced":null,"published":"2026-08-13"}},{"major":"16","fixed_version":"16.15","introduced":null,"published_date":"2026-08-13","facts":{"fixed":"16.15","introduced":null,"published":"2026-08-13"}},{"major":"17","fixed_version":"17.11","introduced":null,"published_date":"2026-08-13","facts":{"fixed":"17.11","introduced":null,"published":"2026-08-13"}},{"major":"18","fixed_version":"18.6","introduced":null,"published_date":"2026-08-13","facts":{"fixed":"18.6","introduced":null,"published":"2026-08-13"}}],"legacy":[{"source":"center","source_id":87,"observed_at":"2026-10-03 12:08:35.169032+08","raw":{"id":87,"cve":"2026-6471","public":true,"vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","details":"PostgreSQL 逻辑解码缺少授权检查，持有 REPLICATION 权限的非超级用户可通过选择逻辑解码插件， 让服务器使用 dlopen 加载数据库服务操作系统账户可见的任意文件，进而以该账户身份执行任意代码。 PostgreSQL 18.6、17.11、16.15、15.19 和 14.24 之前的版本受此问题影响。","component":"core server","cvenumber":202606471,"description":"PostgreSQL 逻辑解码可通过 dlopen 加载任意文件","detailslink":"","legacyscore":"","newspost_id":3365},"fixes":[{"source_id":352,"source_version_id":31,"major":"18","fixed_minor":6,"raw":{"id":352,"patch_id":87,"version_id":31,"fixed_minor":6},"version_raw":{"id":31,"tree":18.0,"current":true,"docsgit":"","eoldate":"2030-11-14","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":6,"firstreldate":"2025-09-25"}},{"source_id":353,"source_version_id":30,"major":"17","fixed_minor":11,"raw":{"id":353,"patch_id":87,"version_id":30,"fixed_minor":11},"version_raw":{"id":30,"tree":17.0,"current":false,"docsgit":"","eoldate":"2029-11-08","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":11,"firstreldate":"2024-09-26"}},{"source_id":354,"source_version_id":29,"major":"16","fixed_minor":15,"raw":{"id":354,"patch_id":87,"version_id":29,"fixed_minor":15},"version_raw":{"id":29,"tree":16.0,"current":false,"docsgit":"","eoldate":"2028-11-09","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":15,"firstreldate":"2023-09-14"}},{"source_id":355,"source_version_id":28,"major":"15","fixed_minor":19,"raw":{"id":355,"patch_id":87,"version_id":28,"fixed_minor":19},"version_raw":{"id":28,"tree":15.0,"current":false,"docsgit":"","eoldate":"2027-11-11","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":19,"firstreldate":"2022-10-13"}},{"source_id":356,"source_version_id":27,"major":"14","fixed_minor":24,"raw":{"id":356,"patch_id":87,"version_id":27,"fixed_minor":24},"version_raw":{"id":27,"tree":14.0,"current":false,"docsgit":"","eoldate":"2026-11-12","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":24,"firstreldate":"2021-09-30"}}]},{"source":"pgweb","source_id":87,"observed_at":"2026-10-03 12:08:55.967155+08","raw":{"id":87,"cve":"2026-6471","public":true,"vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","details":"PostgreSQL 逻辑解码缺少授权检查，持有 REPLICATION 权限的非超级用户可通过选择逻辑解码插件， 让服务器使用 dlopen 加载数据库服务操作系统账户可见的任意文件，进而以该账户身份执行任意代码。 PostgreSQL 18.6、17.11、16.15、15.19 和 14.24 之前的版本受此问题影响。","component":"core server","cvenumber":202606471,"description":"PostgreSQL 逻辑解码可通过 dlopen 加载任意文件","detailslink":"","legacyscore":"","newspost_id":3365},"fixes":[{"source_id":352,"source_version_id":31,"major":"18","fixed_minor":6,"raw":{"id":352,"patch_id":87,"version_id":31,"fixed_minor":6},"version_raw":{"id":31,"tree":18.0,"current":true,"docsgit":"","eoldate":"2030-11-14","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":6,"firstreldate":"2025-09-25"}},{"source_id":353,"source_version_id":30,"major":"17","fixed_minor":11,"raw":{"id":353,"patch_id":87,"version_id":30,"fixed_minor":11},"version_raw":{"id":30,"tree":17.0,"current":false,"docsgit":"","eoldate":"2029-11-08","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":11,"firstreldate":"2024-09-26"}},{"source_id":354,"source_version_id":29,"major":"16","fixed_minor":15,"raw":{"id":354,"patch_id":87,"version_id":29,"fixed_minor":15},"version_raw":{"id":29,"tree":16.0,"current":false,"docsgit":"","eoldate":"2028-11-09","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":15,"firstreldate":"2023-09-14"}},{"source_id":355,"source_version_id":28,"major":"15","fixed_minor":19,"raw":{"id":355,"patch_id":87,"version_id":28,"fixed_minor":19},"version_raw":{"id":28,"tree":15.0,"current":false,"docsgit":"","eoldate":"2027-11-11","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":19,"firstreldate":"2022-10-13"}},{"source_id":356,"source_version_id":27,"major":"14","fixed_minor":24,"raw":{"id":356,"patch_id":87,"version_id":27,"fixed_minor":24},"version_raw":{"id":27,"tree":14.0,"current":false,"docsgit":"","eoldate":"2026-11-12","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":24,"firstreldate":"2021-09-30"}}]}]}
