Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object creator to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.
Metrics
Affected Vendors & Products
References
History
Fri, 20 Feb 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* |
Fri, 13 Feb 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Postgresql
Postgresql postgresql |
|
| Vendors & Products |
Postgresql
Postgresql postgresql |
Fri, 13 Feb 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Thu, 12 Feb 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 12 Feb 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object creator to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected. | |
| Title | PostgreSQL intarray missing validation of type of input to selectivity estimator executes arbitrary code | |
| Weaknesses | CWE-1287 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: PostgreSQL
Published:
Updated: 2026-02-13T04:56:32.981Z
Reserved: 2026-02-05T18:17:54.681Z
Link: CVE-2026-2004
Updated: 2026-02-12T14:32:49.462Z
Status : Analyzed
Published: 2026-02-12T14:16:02.213
Modified: 2026-02-20T19:53:53.960
Link: CVE-2026-2004