OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-96883

HIGH · CVSS 8.8 EPSS 0.65% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-24 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

The pgcollection extension for PostgreSQL is vulnerable due to a type confusion issue that allows authenticated remote users to execute arbitrary code as the postgres operating system user through specially crafted SQL statements. This high-severity vulnerability poses a significant risk to database integrity and security, particularly for organizations utilizing versions 2.0.0 to 2.1.1. Database administrators and security teams should prioritize upgrading to version 2.1.2 or later to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-96883
Severity
HIGH
CVSS
8.8
EPSS
0.65%

Original NVD Description

pgcollection is an open source extension to PostgreSQL. A type confusion issue in AWS pgcollection 2.0.0 through 2.1.1 might allow an authenticated remote user to execute arbitrary code as the postgres operating system user via crafted SQL statements that rely on mismatched type metadata in collection value retrieval and array conversion functions. To remediate this issue, users should upgrade to version 2.1.2 or later.