Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object creator to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.postgresql.org/support/security/CVE-2026-2004/ |
|
History
Thu, 12 Feb 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 12 Feb 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object creator to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected. | |
| Title | PostgreSQL intarray missing validation of type of input to selectivity estimator executes arbitrary code | |
| Weaknesses | CWE-1287 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: PostgreSQL
Published:
Updated: 2026-02-12T14:32:53.686Z
Reserved: 2026-02-05T18:17:54.681Z
Link: CVE-2026-2004
Updated: 2026-02-12T14:32:49.462Z
Status : Awaiting Analysis
Published: 2026-02-12T14:16:02.213
Modified: 2026-02-12T15:10:37.307
Link: CVE-2026-2004
No data.
OpenCVE Enrichment
No data.