{"id":"CVE-2026-6475","year":2026,"sequence":6475,"component":"client","score":8.8,"cvss_version":"3.0","vector":"AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","first_published":"2026-05-14","source_url":"https://www.postgresql.org/support/security/CVE-2026-6475/","facts":{"affected":{"14":"14","15":"15","16":"16","17":"17","18":"18"},"affected_ranges":[{"from":"0","until":"14.23"},{"from":"15","until":"15.18"},{"from":"16","until":"16.14"},{"from":"17","until":"17.10"},{"from":"18","until":"18.4"}],"cna_url":"https://cveawg.mitre.org/api/cve/CVE-2026-6475","component":"client","cvss_version":"3.0","description_en":"Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.","first_published":"2026-05-14","fixed":{"14":"14.23","15":"15.18","16":"16.14","17":"17.10","18":"18.4"},"id":"CVE-2026-6475","introduced":{},"published":{"14":"2026-05-14","15":"2026-05-14","16":"2026-05-14","17":"2026-05-14","18":"2026-05-14"},"score":8.8,"title":"PostgreSQL pg_basebackup and pg_rewind can overwrite unrelated files of origin superuser choice","url":"https://www.postgresql.org/support/security/CVE-2026-6475/","vector":"AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},"reviewed_hash":"6a65a7884245936f6adaef8709d290d460e999dfce1ad78734fa7c9a324ed325","source_hash":"965b9e2323feab543f3cbeb74c418c3a5b43cbefc6594d2862ff0d24dcf8e6a2","text":{"locale":"zh-Hans","title":"PostgreSQL pg_basebackup 与 pg_rewind 可覆盖源端超级用户指定的无关文件","description":"PostgreSQL pg_basebackup 与 pg_rewind 可覆盖源端超级用户指定的无关文件","details":"PostgreSQL pg_basebackup 的 plain 格式及 pg_rewind 会跟随符号链接，使源端超级用户能够覆盖本地文件， 例如通过覆盖 /var/lib/postgres/.bashrc 劫持操作系统账户。由于 shared_preload_libraries 等功能，在这些命令后启动服务器本就隐含信任源端超级用户；因此，只有在命令执行后、服务器启动前采取相关操作 （例如将文件移到另一台虚拟机或创建虚拟机快照）时，此攻击才具有实际影响。PostgreSQL 18.4、17.10、 16.14、15.18 和 14.23 之前的版本受此问题影响。","format":"markdown","provenance":{"identity":"immutable_cve_code","sources":[{"observed_at":"2026-10-03 12:08:35.169032+08","raw":{"component":"client","cve":"2026-6475","cvenumber":202606475,"description":"PostgreSQL pg_basebackup 与 pg_rewind 可覆盖源端超级用户指定的无关文件","details":"PostgreSQL pg_basebackup 的 plain 格式及 pg_rewind 会跟随符号链接，使源端超级用户能够覆盖本地文件， 例如通过覆盖 /var/lib/postgres/.bashrc 劫持操作系统账户。由于 shared_preload_libraries 等功能，在这些命令后启动服务器本就隐含信任源端超级用户；因此，只有在命令执行后、服务器启动前采取相关操作 （例如将文件移到另一台虚拟机或创建虚拟机快照）时，此攻击才具有实际影响。PostgreSQL 18.4、17.10、 16.14、15.18 和 14.23 之前的版本受此问题影响。","detailslink":"","id":43,"legacyscore":"","newspost_id":3294,"public":true,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},"source":"center","source_id":43,"source_table_sha256":"b57ee28b2263464208af0ccf7512b31f0c1ab7140d12dda09a0c87de341f1372"},{"observed_at":"2026-10-03 12:08:55.967155+08","raw":{"component":"client","cve":"2026-6475","cvenumber":202606475,"description":"PostgreSQL pg_basebackup 与 pg_rewind 可覆盖源端超级用户指定的无关文件","details":"PostgreSQL pg_basebackup 的 plain 格式及 pg_rewind 会跟随符号链接，使源端超级用户能够覆盖本地文件， 例如通过覆盖 /var/lib/postgres/.bashrc 劫持操作系统账户。由于 shared_preload_libraries 等功能，在这些命令后启动服务器本就隐含信任源端超级用户；因此，只有在命令执行后、服务器启动前采取相关操作 （例如将文件移到另一台虚拟机或创建虚拟机快照）时，此攻击才具有实际影响。PostgreSQL 18.4、17.10、 16.14、15.18 和 14.23 之前的版本受此问题影响。","detailslink":"","id":43,"legacyscore":"","newspost_id":3294,"public":true,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},"source":"pgweb","source_id":43,"source_table_sha256":"b57ee28b2263464208af0ccf7512b31f0c1ab7140d12dda09a0c87de341f1372"}]},"text_hash":"2d9277679274a4f333f0a25b227fbe748e63f63752397b0058f611fa8e506400"},"locales":["en","zh-Hans"],"fixes":[{"major":"14","fixed_version":"14.23","introduced":null,"published_date":"2026-05-14","facts":{"fixed":"14.23","introduced":null,"published":"2026-05-14"}},{"major":"15","fixed_version":"15.18","introduced":null,"published_date":"2026-05-14","facts":{"fixed":"15.18","introduced":null,"published":"2026-05-14"}},{"major":"16","fixed_version":"16.14","introduced":null,"published_date":"2026-05-14","facts":{"fixed":"16.14","introduced":null,"published":"2026-05-14"}},{"major":"17","fixed_version":"17.10","introduced":null,"published_date":"2026-05-14","facts":{"fixed":"17.10","introduced":null,"published":"2026-05-14"}},{"major":"18","fixed_version":"18.4","introduced":null,"published_date":"2026-05-14","facts":{"fixed":"18.4","introduced":null,"published":"2026-05-14"}}],"legacy":[{"source":"center","source_id":43,"observed_at":"2026-10-03 12:08:35.169032+08","raw":{"id":43,"cve":"2026-6475","public":true,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","details":"PostgreSQL pg_basebackup 的 plain 格式及 pg_rewind 会跟随符号链接，使源端超级用户能够覆盖本地文件， 例如通过覆盖 /var/lib/postgres/.bashrc 劫持操作系统账户。由于 shared_preload_libraries 等功能，在这些命令后启动服务器本就隐含信任源端超级用户；因此，只有在命令执行后、服务器启动前采取相关操作 （例如将文件移到另一台虚拟机或创建虚拟机快照）时，此攻击才具有实际影响。PostgreSQL 18.4、17.10、 16.14、15.18 和 14.23 之前的版本受此问题影响。","component":"client","cvenumber":202606475,"description":"PostgreSQL pg_basebackup 与 pg_rewind 可覆盖源端超级用户指定的无关文件","detailslink":"","legacyscore":"","newspost_id":3294},"fixes":[{"source_id":152,"source_version_id":31,"major":"18","fixed_minor":4,"raw":{"id":152,"patch_id":43,"version_id":31,"fixed_minor":4},"version_raw":{"id":31,"tree":18.0,"current":true,"docsgit":"","eoldate":"2030-11-14","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":6,"firstreldate":"2025-09-25"}},{"source_id":153,"source_version_id":30,"major":"17","fixed_minor":10,"raw":{"id":153,"patch_id":43,"version_id":30,"fixed_minor":10},"version_raw":{"id":30,"tree":17.0,"current":false,"docsgit":"","eoldate":"2029-11-08","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":11,"firstreldate":"2024-09-26"}},{"source_id":154,"source_version_id":29,"major":"16","fixed_minor":14,"raw":{"id":154,"patch_id":43,"version_id":29,"fixed_minor":14},"version_raw":{"id":29,"tree":16.0,"current":false,"docsgit":"","eoldate":"2028-11-09","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":15,"firstreldate":"2023-09-14"}},{"source_id":155,"source_version_id":28,"major":"15","fixed_minor":18,"raw":{"id":155,"patch_id":43,"version_id":28,"fixed_minor":18},"version_raw":{"id":28,"tree":15.0,"current":false,"docsgit":"","eoldate":"2027-11-11","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":19,"firstreldate":"2022-10-13"}},{"source_id":156,"source_version_id":27,"major":"14","fixed_minor":23,"raw":{"id":156,"patch_id":43,"version_id":27,"fixed_minor":23},"version_raw":{"id":27,"tree":14.0,"current":false,"docsgit":"","eoldate":"2026-11-12","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":24,"firstreldate":"2021-09-30"}}]},{"source":"pgweb","source_id":43,"observed_at":"2026-10-03 12:08:55.967155+08","raw":{"id":43,"cve":"2026-6475","public":true,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","details":"PostgreSQL pg_basebackup 的 plain 格式及 pg_rewind 会跟随符号链接，使源端超级用户能够覆盖本地文件， 例如通过覆盖 /var/lib/postgres/.bashrc 劫持操作系统账户。由于 shared_preload_libraries 等功能，在这些命令后启动服务器本就隐含信任源端超级用户；因此，只有在命令执行后、服务器启动前采取相关操作 （例如将文件移到另一台虚拟机或创建虚拟机快照）时，此攻击才具有实际影响。PostgreSQL 18.4、17.10、 16.14、15.18 和 14.23 之前的版本受此问题影响。","component":"client","cvenumber":202606475,"description":"PostgreSQL pg_basebackup 与 pg_rewind 可覆盖源端超级用户指定的无关文件","detailslink":"","legacyscore":"","newspost_id":3294},"fixes":[{"source_id":152,"source_version_id":31,"major":"18","fixed_minor":4,"raw":{"id":152,"patch_id":43,"version_id":31,"fixed_minor":4},"version_raw":{"id":31,"tree":18.0,"current":true,"docsgit":"","eoldate":"2030-11-14","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":6,"firstreldate":"2025-09-25"}},{"source_id":153,"source_version_id":30,"major":"17","fixed_minor":10,"raw":{"id":153,"patch_id":43,"version_id":30,"fixed_minor":10},"version_raw":{"id":30,"tree":17.0,"current":false,"docsgit":"","eoldate":"2029-11-08","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":11,"firstreldate":"2024-09-26"}},{"source_id":154,"source_version_id":29,"major":"16","fixed_minor":14,"raw":{"id":154,"patch_id":43,"version_id":29,"fixed_minor":14},"version_raw":{"id":29,"tree":16.0,"current":false,"docsgit":"","eoldate":"2028-11-09","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":15,"firstreldate":"2023-09-14"}},{"source_id":155,"source_version_id":28,"major":"15","fixed_minor":18,"raw":{"id":155,"patch_id":43,"version_id":28,"fixed_minor":18},"version_raw":{"id":28,"tree":15.0,"current":false,"docsgit":"","eoldate":"2027-11-11","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":19,"firstreldate":"2022-10-13"}},{"source_id":156,"source_version_id":27,"major":"14","fixed_minor":23,"raw":{"id":156,"patch_id":43,"version_id":27,"fixed_minor":23},"version_raw":{"id":27,"tree":14.0,"current":false,"docsgit":"","eoldate":"2026-11-12","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":24,"firstreldate":"2021-09-30"}}]}]}
