AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-16238

HIGH · CVSS 8.8 EPSS 0.59%

Source: NVD + CISA KEV + EPSS · Published 2026-08-13 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

A type confusion vulnerability in PostgreSQL's pg_restore_attribute_stats() function allows an attacker to execute arbitrary code with the privileges of the operating system user running the database. This issue affects PostgreSQL version 18 and earlier minor versions prior to 18.5, making it critical for organizations using these versions to prioritize patching to mitigate potential exploitation risks.

CVE
CVE-2026-16238
Severity
HIGH
CVSS
8.8
EPSS
0.59%

Original NVD Description

Type confusion in PostgreSQL pg_restore_attribute_stats() allows an object creator to execute arbitrary code as the operating system user running the database, via conflation of range and multirange values. Within major version 18, minor versions before PostgreSQL 18.5 are affected. Versions before PostgreSQL 18 are unaffected.