AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-14668

HIGH · CVSS 8.1 EPSS 0.45%

Source: NVD + CISA KEV + EPSS · Published 2026-08-13 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

A type confusion vulnerability in PostgreSQL's ctid data type selectivity estimator allows an attacker to access and view calculations derived from arbitrary memory spans, potentially leading to the recovery of sensitive data. This issue affects versions prior to PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24. Database administrators and organizations using these affected versions should prioritize patching to mitigate the risk of data exposure.

CVE
CVE-2026-14668
Severity
HIGH
CVSS
8.1
EPSS
0.45%

Original NVD Description

Type confusion regarding input of PostgreSQL ctid data type selectivity estimator allows an object creator to view a calculation derived from the value of an arbitrary 4-byte span of memory, via a chosen non-ctid input. While the calculation loses precision, substantial memory value recovery appears possible. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.