{"id":"CVE-2026-6476","year":2026,"sequence":6476,"component":"client","score":7.2,"cvss_version":"3.0","vector":"AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","first_published":"2026-05-14","source_url":"https://www.postgresql.org/support/security/CVE-2026-6476/","facts":{"affected":{"17":"17","18":"18"},"affected_ranges":[{"from":"17","until":"17.10"},{"from":"18","until":"18.4"}],"cna_url":"https://cveawg.mitre.org/api/cve/CVE-2026-6476","component":"client","cvss_version":"3.0","description_en":"SQL injection in PostgreSQL pg_createsubscriber allows an attacker with pg_create_subscription rights to execute arbitrary SQL as a superuser. The attack takes effect when pg_createsubscriber next runs. Within major versions 17 and 18, minor versions before PostgreSQL 18.4 and 17.10 are affected. Versions before PostgreSQL 17 are unaffected.","first_published":"2026-05-14","fixed":{"17":"17.10","18":"18.4"},"id":"CVE-2026-6476","introduced":{},"published":{"17":"2026-05-14","18":"2026-05-14"},"score":7.2,"title":"PostgreSQL pg_createsubscriber allows SQL injection via subscription name","url":"https://www.postgresql.org/support/security/CVE-2026-6476/","vector":"AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"},"reviewed_hash":"6a65a7884245936f6adaef8709d290d460e999dfce1ad78734fa7c9a324ed325","source_hash":"965b9e2323feab543f3cbeb74c418c3a5b43cbefc6594d2862ff0d24dcf8e6a2","text":{"locale":"zh-Hans","title":"PostgreSQL pg_createsubscriber 可通过订阅名称实施 SQL 注入","description":"PostgreSQL pg_createsubscriber 可通过订阅名称实施 SQL 注入","details":"PostgreSQL pg_createsubscriber 中的 SQL 注入允许拥有 pg_create_subscription 权限的攻击者 以超级用户身份执行任意 SQL；攻击会在下次运行 pg_createsubscriber 时生效。在主版本 17 和 18 中， PostgreSQL 18.4 与 17.10 之前的小版本受此问题影响，PostgreSQL 17 之前的版本不受影响。","format":"markdown","provenance":{"identity":"immutable_cve_code","sources":[{"observed_at":"2026-10-03 12:08:35.169032+08","raw":{"component":"client","cve":"2026-6476","cvenumber":202606476,"description":"PostgreSQL pg_createsubscriber 可通过订阅名称实施 SQL 注入","details":"PostgreSQL pg_createsubscriber 中的 SQL 注入允许拥有 pg_create_subscription 权限的攻击者 以超级用户身份执行任意 SQL；攻击会在下次运行 pg_createsubscriber 时生效。在主版本 17 和 18 中， PostgreSQL 18.4 与 17.10 之前的小版本受此问题影响，PostgreSQL 17 之前的版本不受影响。","detailslink":"","id":44,"legacyscore":"","newspost_id":3294,"public":true,"vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"},"source":"center","source_id":44,"source_table_sha256":"b57ee28b2263464208af0ccf7512b31f0c1ab7140d12dda09a0c87de341f1372"},{"observed_at":"2026-10-03 12:08:55.967155+08","raw":{"component":"client","cve":"2026-6476","cvenumber":202606476,"description":"PostgreSQL pg_createsubscriber 可通过订阅名称实施 SQL 注入","details":"PostgreSQL pg_createsubscriber 中的 SQL 注入允许拥有 pg_create_subscription 权限的攻击者 以超级用户身份执行任意 SQL；攻击会在下次运行 pg_createsubscriber 时生效。在主版本 17 和 18 中， PostgreSQL 18.4 与 17.10 之前的小版本受此问题影响，PostgreSQL 17 之前的版本不受影响。","detailslink":"","id":44,"legacyscore":"","newspost_id":3294,"public":true,"vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"},"source":"pgweb","source_id":44,"source_table_sha256":"b57ee28b2263464208af0ccf7512b31f0c1ab7140d12dda09a0c87de341f1372"}]},"text_hash":"53ac7874a38e9ab966a365fb67a74580120d114cea2cc223a79392a19cb2846c"},"locales":["en","zh-Hans"],"fixes":[{"major":"17","fixed_version":"17.10","introduced":null,"published_date":"2026-05-14","facts":{"fixed":"17.10","introduced":null,"published":"2026-05-14"}},{"major":"18","fixed_version":"18.4","introduced":null,"published_date":"2026-05-14","facts":{"fixed":"18.4","introduced":null,"published":"2026-05-14"}}],"legacy":[{"source":"center","source_id":44,"observed_at":"2026-10-03 12:08:35.169032+08","raw":{"id":44,"cve":"2026-6476","public":true,"vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","details":"PostgreSQL pg_createsubscriber 中的 SQL 注入允许拥有 pg_create_subscription 权限的攻击者 以超级用户身份执行任意 SQL；攻击会在下次运行 pg_createsubscriber 时生效。在主版本 17 和 18 中， PostgreSQL 18.4 与 17.10 之前的小版本受此问题影响，PostgreSQL 17 之前的版本不受影响。","component":"client","cvenumber":202606476,"description":"PostgreSQL pg_createsubscriber 可通过订阅名称实施 SQL 注入","detailslink":"","legacyscore":"","newspost_id":3294},"fixes":[{"source_id":157,"source_version_id":31,"major":"18","fixed_minor":4,"raw":{"id":157,"patch_id":44,"version_id":31,"fixed_minor":4},"version_raw":{"id":31,"tree":18.0,"current":true,"docsgit":"","eoldate":"2030-11-14","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":6,"firstreldate":"2025-09-25"}},{"source_id":158,"source_version_id":30,"major":"17","fixed_minor":10,"raw":{"id":158,"patch_id":44,"version_id":30,"fixed_minor":10},"version_raw":{"id":30,"tree":17.0,"current":false,"docsgit":"","eoldate":"2029-11-08","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":11,"firstreldate":"2024-09-26"}}]},{"source":"pgweb","source_id":44,"observed_at":"2026-10-03 12:08:55.967155+08","raw":{"id":44,"cve":"2026-6476","public":true,"vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","details":"PostgreSQL pg_createsubscriber 中的 SQL 注入允许拥有 pg_create_subscription 权限的攻击者 以超级用户身份执行任意 SQL；攻击会在下次运行 pg_createsubscriber 时生效。在主版本 17 和 18 中， PostgreSQL 18.4 与 17.10 之前的小版本受此问题影响，PostgreSQL 17 之前的版本不受影响。","component":"client","cvenumber":202606476,"description":"PostgreSQL pg_createsubscriber 可通过订阅名称实施 SQL 注入","detailslink":"","legacyscore":"","newspost_id":3294},"fixes":[{"source_id":157,"source_version_id":31,"major":"18","fixed_minor":4,"raw":{"id":157,"patch_id":44,"version_id":31,"fixed_minor":4},"version_raw":{"id":31,"tree":18.0,"current":true,"docsgit":"","eoldate":"2030-11-14","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":6,"firstreldate":"2025-09-25"}},{"source_id":158,"source_version_id":30,"major":"17","fixed_minor":10,"raw":{"id":158,"patch_id":44,"version_id":30,"fixed_minor":10},"version_raw":{"id":30,"tree":17.0,"current":false,"docsgit":"","eoldate":"2029-11-08","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":11,"firstreldate":"2024-09-26"}}]}]}
