CVE-2026-83534CWE-250

PostgreSQL Anonymizer: Privilege escalation to superuser via anon.anonymize_database_parallel()

Medium · published September 6, 2026

CVSS v3.1
6.4
EPSS
In the wild
Unconfirmed
What it is

PostgreSQL Anonymizer contains a vulnerability in the anon.anonymize_database_parallel() function that allows the owner of a table to run arbitrary code with superuser privilege. The issue is fixed in PostgreSQL Anonymizer 3.2.0 and later versions

The record
Technical detail
CVSS v3.1
6.4 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
Not scored
Weakness
CWE-250 · Execution with Unnecessary Privileges
Published
2026-09-06T15:25Z
Timeline
  • 06 SEP 15:25Z
    PostgreSQL Anonymizer: Privilege escalation to superuser via anon.anonymize_database_parallel()
    cvelistv5