Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.postgresql.org/support/security/CVE-2026-16239/ |
|
Thu, 13 Aug 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Postgresql
Postgresql postgresql |
|
| Vendors & Products |
Postgresql
Postgresql postgresql |
Thu, 13 Aug 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Type confusion in PostgreSQL "portal"/cursor lifecycle allows a user to execute arbitrary code as the operating system user running the database, via re-creation of a cursor or other portal with different types. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected. | |
| Title | PostgreSQL type confusion in cursor CLOSE + DECLARE executes arbitrary code | |
| Weaknesses | CWE-843 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: PostgreSQL
Published:
Updated: 2026-08-13T15:38:30.542Z
Reserved: 2026-07-20T01:55:33.311Z
Link: CVE-2026-16239
No data.
Status : Received
Published: 2026-08-13T13:17:46.520
Modified: 2026-08-13T13:17:46.520
Link: CVE-2026-16239
No data.
OpenCVE Enrichment
Updated: 2026-08-13T14:45:03Z