AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-14669

HIGH · CVSS 8.8 EPSS 0.60%

Source: NVD + CISA KEV + EPSS · Published 2026-08-13 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

A heap buffer overflow vulnerability in PostgreSQL's to_char(timestamptz) function allows an attacker to execute arbitrary code with the privileges of the database's operating system user by providing a long POSIX timezone abbreviation. This high-severity flaw affects versions prior to 18.5, 17.11, 16.15, 15.19, and 14.24, and should be prioritized by organizations using these PostgreSQL versions to mitigate potential exploitation risks. Database administrators and security teams should urgently apply the necessary updates to protect against this vulnerability.

CVE
CVE-2026-14669
Severity
HIGH
CVSS
8.8
EPSS
0.60%

Original NVD Description

Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the party choosing the timezone to execute arbitrary code as the operating system user running the database, via a long POSIX timezone abbreviation. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.