AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-14676

HIGH · CVSS 8.8 EPSS 0.60%

Source: NVD + CISA KEV + EPSS · Published 2026-08-13 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

A heap buffer overflow vulnerability in PostgreSQL's pg_stat_statements allows attackers to execute arbitrary code as the database's operating system user by crafting specific queries with array constants. This high-severity issue affects PostgreSQL version 18 and minor versions prior to 18.5, making it critical for database administrators using these versions to prioritize patching to mitigate potential exploitation risks.

CVE
CVE-2026-14676
Severity
HIGH
CVSS
8.8
EPSS
0.60%

Original NVD Description

Heap buffer overflow in PostgreSQL pg_stat_statements allows the query author to execute arbitrary code as the operating system user running the database, via crafted queries containing array constants. Within major version 18, minor versions before PostgreSQL 18.5 are affected. Versions before PostgreSQL 18 are unaffected.