< BACK TO NEWS
importantSYS.SOURCE: The Hacker News2026-09-04T20:50:19+05:30

PostgreSQL Addresses 12-Year-Old Logical Decoding Vulnerability Permitting Replication-Role Code Execution

PostgreSQL addressed CVE-2026-6471, a 12-year-old logical decoding vulnerability allowing replication-role code execution by restricting output plugin libraries. The fix requires updating to patched versions and configuring output_plugin_libraries to prevent unauthorized library loading.

PostgreSQL has released updates to address a security flaw that allows an account with the REPLICATION attribute to run arbitrary code as the operating-system user running the database server.

The flaw, tracked as CVE-2026-6471 (CVSS score: 7.2), has been present since logical decoding was introduced in PostgreSQL 9.4 in 2014. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are

Read original article

*** END OF TRANSMISSION ***