CVE-2026-6476

EUVD-2026-30285
SQL injection in PostgreSQL pg_createsubscriber allows an attacker with pg_create_subscription rights to execute arbitrary SQL as a superuser.  The attack takes effect when pg_createsubscriber next runs.  Within major versions 17 and 18, minor versions before PostgreSQL 18.4 and 17.10 are affected.  Versions before PostgreSQL 17 are unaffected.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 20%
Affected Products (NVD)
VendorProductVersion
postgresqlpostgresql
17.0 ≤
𝑥
< 17.10
postgresqlpostgresql
18.0 ≤
𝑥
< 18.4
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
postgresql-17
trixie
vulnerable
trixie (security)
17.10-0+deb13u1
fixed
postgresql-18
forky
18.4-1
fixed
sid
18.4-1
fixed
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libecpg6
suse enterprise sap 15 SP7
18.4-150600.13.11.1
fixed
suse enterprise server 12 SP3
17.10-3.27.1
fixed
suse enterprise server 12 SP5
18.4-8.12.1
fixed
suse enterprise server 15 SP4
18.4-150200.5.12.1
fixed
suse enterprise server 15 SP5
18.4-150200.5.12.1
fixed
suse enterprise server 15 SP6
18.4-150600.13.11.1
fixed
suse enterprise server 15 SP7
18.4-150600.13.11.1
fixed
libecpg6-32bit
suse enterprise server 12 SP3
17.10-3.27.1
fixed
suse enterprise server 12 SP5
18.4-8.12.1
fixed
libpq5
suse enterprise desktop 15 SP7
18.4-150600.13.11.1
fixed
suse enterprise sap 15 SP7
18.4-150600.13.11.1
fixed
suse enterprise server 12 SP3
17.10-3.27.1
fixed
suse enterprise server 12 SP5
18.4-8.12.1
fixed
suse enterprise server 15 SP4
18.4-150200.5.12.1
fixed
suse enterprise server 15 SP5
18.4-150200.5.12.1
fixed
suse enterprise server 15 SP6
18.4-150600.13.11.1
fixed
suse enterprise server 15 SP7
18.4-150600.13.11.1
fixed
libpq5-32bit
suse enterprise desktop 15 SP7
18.4-150600.13.11.1
fixed
suse enterprise sap 15 SP7
18.4-150600.13.11.1
fixed
suse enterprise server 12 SP3
17.10-3.27.1
fixed
suse enterprise server 12 SP5
18.4-8.12.1
fixed
suse enterprise server 15 SP4
18.4-150200.5.12.1
fixed
suse enterprise server 15 SP5
18.4-150200.5.12.1
fixed
suse enterprise server 15 SP6
18.4-150600.13.11.1
fixed
suse enterprise server 15 SP7
18.4-150600.13.11.1
fixed
postgresql17
suse enterprise desktop 15 SP7
17.10-150600.13.27.1
fixed
suse enterprise sap 15 SP7
17.10-150600.13.27.1
fixed
suse enterprise server 15 SP5
17.10-150200.5.28.1
fixed
suse enterprise server 15 SP6
17.10-150600.13.27.1
fixed
suse enterprise server 15 SP7
17.10-150600.13.27.1
fixed
postgresql17-contrib
suse enterprise sap 15 SP7
17.10-150600.13.27.1
fixed
suse enterprise server 15 SP5
17.10-150200.5.28.1
fixed
suse enterprise server 15 SP6
17.10-150600.13.27.1
fixed
suse enterprise server 15 SP7
17.10-150600.13.27.1
fixed
postgresql17-devel
suse enterprise sap 15 SP7
17.10-150600.13.27.1
fixed
suse enterprise server 15 SP5
17.10-150200.5.28.1
fixed
suse enterprise server 15 SP6
17.10-150600.13.27.1
fixed
suse enterprise server 15 SP7
17.10-150600.13.27.1
fixed
postgresql17-docs
suse enterprise sap 15 SP7
17.10-150600.13.27.1
fixed
suse enterprise server 15 SP5
17.10-150200.5.28.1
fixed
suse enterprise server 15 SP6
17.10-150600.13.27.1
fixed
suse enterprise server 15 SP7
17.10-150600.13.27.1
fixed
postgresql17-llvmjit
suse enterprise server 15 SP5
17.10-150200.5.28.1
fixed
postgresql17-llvmjit-devel
suse enterprise server 15 SP5
17.10-150200.5.28.1
fixed
postgresql17-plperl
suse enterprise sap 15 SP7
17.10-150600.13.27.1
fixed
suse enterprise server 15 SP5
17.10-150200.5.28.1
fixed
suse enterprise server 15 SP6
17.10-150600.13.27.1
fixed
suse enterprise server 15 SP7
17.10-150600.13.27.1
fixed
postgresql17-plpython
suse enterprise sap 15 SP7
17.10-150600.13.27.1
fixed
suse enterprise server 15 SP5
17.10-150200.5.28.1
fixed
suse enterprise server 15 SP6
17.10-150600.13.27.1
fixed
suse enterprise server 15 SP7
17.10-150600.13.27.1
fixed
postgresql17-pltcl
suse enterprise sap 15 SP7
17.10-150600.13.27.1
fixed
suse enterprise server 15 SP5
17.10-150200.5.28.1
fixed
suse enterprise server 15 SP6
17.10-150600.13.27.1
fixed
suse enterprise server 15 SP7
17.10-150600.13.27.1
fixed
postgresql17-server
suse enterprise sap 15 SP7
17.10-150600.13.27.1
fixed
suse enterprise server 15 SP5
17.10-150200.5.28.1
fixed
suse enterprise server 15 SP6
17.10-150600.13.27.1
fixed
suse enterprise server 15 SP7
17.10-150600.13.27.1
fixed
postgresql17-server-devel
suse enterprise sap 15 SP7
17.10-150600.13.27.1
fixed
suse enterprise server 15 SP5
17.10-150200.5.28.1
fixed
suse enterprise server 15 SP6
17.10-150600.13.27.1
fixed
suse enterprise server 15 SP7
17.10-150600.13.27.1
fixed
postgresql18
suse enterprise desktop 15 SP7
18.4-150600.13.11.1
fixed
suse enterprise sap 15 SP7
18.4-150600.13.11.1
fixed
suse enterprise server 15 SP6
18.4-150600.13.11.1
fixed
suse enterprise server 15 SP7
18.4-150600.13.11.1
fixed
postgresql18-contrib
suse enterprise sap 15 SP7
18.4-150600.13.11.1
fixed
suse enterprise server 15 SP6
18.4-150600.13.11.1
fixed
suse enterprise server 15 SP7
18.4-150600.13.11.1
fixed
postgresql18-devel
suse enterprise sap 15 SP7
18.4-150600.13.11.1
fixed
suse enterprise server 15 SP6
18.4-150600.13.11.1
fixed
suse enterprise server 15 SP7
18.4-150600.13.11.1
fixed
postgresql18-docs
suse enterprise sap 15 SP7
18.4-150600.13.11.1
fixed
suse enterprise server 15 SP6
18.4-150600.13.11.1
fixed
suse enterprise server 15 SP7
18.4-150600.13.11.1
fixed
postgresql18-plperl
suse enterprise sap 15 SP7
18.4-150600.13.11.1
fixed
suse enterprise server 15 SP6
18.4-150600.13.11.1
fixed
suse enterprise server 15 SP7
18.4-150600.13.11.1
fixed
postgresql18-plpython
suse enterprise sap 15 SP7
18.4-150600.13.11.1
fixed
suse enterprise server 15 SP6
18.4-150600.13.11.1
fixed
suse enterprise server 15 SP7
18.4-150600.13.11.1
fixed
postgresql18-pltcl
suse enterprise sap 15 SP7
18.4-150600.13.11.1
fixed
suse enterprise server 15 SP6
18.4-150600.13.11.1
fixed
suse enterprise server 15 SP7
18.4-150600.13.11.1
fixed
postgresql18-server
suse enterprise sap 15 SP7
18.4-150600.13.11.1
fixed
suse enterprise server 15 SP6
18.4-150600.13.11.1
fixed
suse enterprise server 15 SP7
18.4-150600.13.11.1
fixed
postgresql18-server-devel
suse enterprise sap 15 SP7
18.4-150600.13.11.1
fixed
suse enterprise server 15 SP6
18.4-150600.13.11.1
fixed
suse enterprise server 15 SP7
18.4-150600.13.11.1
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
postgresql17
Amazon Linux 2023
0:17.10-1.amzn2023.0.1
fixed
postgresql17-contrib
Amazon Linux 2023
0:17.10-1.amzn2023.0.1
fixed
postgresql17-contrib-debuginfo
Amazon Linux 2023
0:17.10-1.amzn2023.0.1
fixed
postgresql17-debuginfo
Amazon Linux 2023
0:17.10-1.amzn2023.0.1
fixed
postgresql17-debugsource
Amazon Linux 2023
0:17.10-1.amzn2023.0.1
fixed
postgresql17-docs
Amazon Linux 2023
0:17.10-1.amzn2023.0.1
fixed
postgresql17-docs-debuginfo
Amazon Linux 2023
0:17.10-1.amzn2023.0.1
fixed
postgresql17-llvmjit
Amazon Linux 2023
0:17.10-1.amzn2023.0.1
fixed
postgresql17-llvmjit-debuginfo
Amazon Linux 2023
0:17.10-1.amzn2023.0.1
fixed
postgresql17-plperl
Amazon Linux 2023
0:17.10-1.amzn2023.0.1
fixed
postgresql17-plperl-debuginfo
Amazon Linux 2023
0:17.10-1.amzn2023.0.1
fixed
postgresql17-plpython3
Amazon Linux 2023
0:17.10-1.amzn2023.0.1
fixed
postgresql17-plpython3-debuginfo
Amazon Linux 2023
0:17.10-1.amzn2023.0.1
fixed
postgresql17-pltcl
Amazon Linux 2023
0:17.10-1.amzn2023.0.1
fixed
postgresql17-pltcl-debuginfo
Amazon Linux 2023
0:17.10-1.amzn2023.0.1
fixed
postgresql17-private-devel
Amazon Linux 2023
0:17.10-1.amzn2023.0.1
fixed
postgresql17-private-libs
Amazon Linux 2023
0:17.10-1.amzn2023.0.1
fixed
postgresql17-private-libs-debuginfo
Amazon Linux 2023
0:17.10-1.amzn2023.0.1
fixed
postgresql17-server
Amazon Linux 2023
0:17.10-1.amzn2023.0.1
fixed
postgresql17-server-debuginfo
Amazon Linux 2023
0:17.10-1.amzn2023.0.1
fixed
postgresql17-server-devel
Amazon Linux 2023
0:17.10-1.amzn2023.0.1
fixed
postgresql17-server-devel-debuginfo
Amazon Linux 2023
0:17.10-1.amzn2023.0.1
fixed
postgresql17-static
Amazon Linux 2023
0:17.10-1.amzn2023.0.1
fixed
postgresql17-test
Amazon Linux 2023
0:17.10-1.amzn2023.0.1
fixed
postgresql17-test-debuginfo
Amazon Linux 2023
0:17.10-1.amzn2023.0.1
fixed
postgresql17-test-rpm-macros
Amazon Linux 2023
0:17.10-1.amzn2023.0.1
fixed
postgresql17-upgrade
Amazon Linux 2023
0:17.10-1.amzn2023.0.1
fixed
postgresql17-upgrade-debuginfo
Amazon Linux 2023
0:17.10-1.amzn2023.0.1
fixed
postgresql17-upgrade-devel
Amazon Linux 2023
0:17.10-1.amzn2023.0.1
fixed
postgresql17-upgrade-devel-debuginfo
Amazon Linux 2023
0:17.10-1.amzn2023.0.1
fixed
postgresql18
Amazon Linux 2023
0:18.4-1.amzn2023.0.1
fixed
postgresql18-contrib
Amazon Linux 2023
0:18.4-1.amzn2023.0.1
fixed
postgresql18-contrib-debuginfo
Amazon Linux 2023
0:18.4-1.amzn2023.0.1
fixed
postgresql18-debuginfo
Amazon Linux 2023
0:18.4-1.amzn2023.0.1
fixed
postgresql18-debugsource
Amazon Linux 2023
0:18.4-1.amzn2023.0.1
fixed
postgresql18-docs
Amazon Linux 2023
0:18.4-1.amzn2023.0.1
fixed
postgresql18-docs-debuginfo
Amazon Linux 2023
0:18.4-1.amzn2023.0.1
fixed
postgresql18-llvmjit
Amazon Linux 2023
0:18.4-1.amzn2023.0.1
fixed
postgresql18-llvmjit-debuginfo
Amazon Linux 2023
0:18.4-1.amzn2023.0.1
fixed
postgresql18-plperl
Amazon Linux 2023
0:18.4-1.amzn2023.0.1
fixed
postgresql18-plperl-debuginfo
Amazon Linux 2023
0:18.4-1.amzn2023.0.1
fixed
postgresql18-plpython3
Amazon Linux 2023
0:18.4-1.amzn2023.0.1
fixed
postgresql18-plpython3-debuginfo
Amazon Linux 2023
0:18.4-1.amzn2023.0.1
fixed
postgresql18-pltcl
Amazon Linux 2023
0:18.4-1.amzn2023.0.1
fixed
postgresql18-pltcl-debuginfo
Amazon Linux 2023
0:18.4-1.amzn2023.0.1
fixed
postgresql18-private-devel
Amazon Linux 2023
0:18.4-1.amzn2023.0.1
fixed
postgresql18-private-libs
Amazon Linux 2023
0:18.4-1.amzn2023.0.1
fixed
postgresql18-private-libs-debuginfo
Amazon Linux 2023
0:18.4-1.amzn2023.0.1
fixed
postgresql18-server
Amazon Linux 2023
0:18.4-1.amzn2023.0.1
fixed
postgresql18-server-debuginfo
Amazon Linux 2023
0:18.4-1.amzn2023.0.1
fixed
postgresql18-server-devel
Amazon Linux 2023
0:18.4-1.amzn2023.0.1
fixed
postgresql18-server-devel-debuginfo
Amazon Linux 2023
0:18.4-1.amzn2023.0.1
fixed
postgresql18-static
Amazon Linux 2023
0:18.4-1.amzn2023.0.1
fixed
postgresql18-test
Amazon Linux 2023
0:18.4-1.amzn2023.0.1
fixed
postgresql18-test-debuginfo
Amazon Linux 2023
0:18.4-1.amzn2023.0.1
fixed
postgresql18-test-rpm-macros
Amazon Linux 2023
0:18.4-1.amzn2023.0.1
fixed
postgresql18-upgrade
Amazon Linux 2023
0:18.4-1.amzn2023.0.1
fixed
postgresql18-upgrade-debuginfo
Amazon Linux 2023
0:18.4-1.amzn2023.0.1
fixed
postgresql18-upgrade-devel
Amazon Linux 2023
0:18.4-1.amzn2023.0.1
fixed
postgresql18-upgrade-devel-debuginfo
Amazon Linux 2023
0:18.4-1.amzn2023.0.1
fixed