CVE-2026-14666CWE-1250

CVE-2026-14666

Medium · published August 13, 2026

CVSS v3.1
4.2
EPSS
0%
Percentile
7.1
In the wild
Unconfirmed
What it is

Incomplete tracking in PostgreSQL of changes to role membership, role attributes, and database ownership allows a query to continue using cached row-level security policies after those changes require a different policy, via plan reuse. Stale policies continue until some other event invalidates the cache or connection termination ends the session. This permits a user to complete reads and modifications that were recently permitted but now forbidden. An attacker must tailor an attack to a particular application's pattern of privilege removal and role-specific row security policies. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

The record
Technical detail
CVSS v3.1
4.2 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
CVSS v4.0
Not supplied
EPSS
0.00175 · 7.1th percentile
Weakness
CWE-1250 · Improper Preservation of Consistency Between Independent Representations of Shared State
Published
2026-08-13T17:17Z
Affected products (5)
ProductVersionsFixed in
postgresql/postgresql≥ 14.0, < 14.2414.24
postgresql/postgresql≥ 15.0, < 15.1915.19
postgresql/postgresql≥ 16.0, < 16.1516.15
postgresql/postgresql≥ 17.0, < 17.1117.11
postgresql/postgresql≥ 18.0, < 18.518.5
References (1)
EPSS history
Timeline
  • 13 AUG 13:00Z
    PostgreSQL row security caching disregards role modifications
    cvelistv5