AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-14671

HIGH · CVSS 8.8 EPSS 0.40%

Source: NVD + CISA KEV + EPSS · Published 2026-08-13 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

A type confusion vulnerability in the PostgreSQL "refint" module allows an object creator to execute arbitrary code with the privileges of the operating system user running the database. This high-severity flaw affects versions prior to PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24, and poses a significant risk to database administrators and organizations using these versions. Immediate prioritization is recommended for users of affected PostgreSQL versions to mitigate potential exploitation.

CVE
CVE-2026-14671
Severity
HIGH
CVSS
8.8
EPSS
0.40%

Original NVD Description

Type confusion in PostgreSQL module "refint" allows an object creator to execute arbitrary code as the operating system user running the database. The fix for this emerged as a non-security bug report, and the fix appear in the git repository with subject "refint: Remove plan cache.", without a CVE number. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.