Security News

12-Year-Old PostgreSQL Flaw Could Let Attackers Hijack Your Database and Server

Security Week · 4 Sept 2026
Key Takeaway If your business uses PostgreSQL databases (directly or via a vendor), check for and apply security updates immediately and audit who has replication-level database access.

Security researchers have disclosed CVE-2026-6471, a critical vulnerability in PostgreSQL that has reportedly existed undetected for 12 years. Named PostGREShell, the flaw allows an attacker who already has low-level replication access to a database to escalate their privileges to full superuser status, execute arbitrary code, and install a persistent backdoor that can survive even after the initial access point is closed.

PostgreSQL is one of the most widely used open-source database systems, powering everything from small business applications to large enterprise platforms. A vulnerability of this severity is concerning because it doesn't require an attacker to start with high-level access — replication access, which is often used for backup or data-syncing purposes, is enough to eventually gain complete control over the database and potentially the underlying server.

For Australian small businesses that rely on PostgreSQL, either directly or through third-party software and hosting providers, this vulnerability underscores the importance of promptly applying vendor patches once available and reviewing who has replication or administrative access to database systems. Businesses should also check with their software vendors or IT providers to confirm whether their systems are affected and what remediation steps are being taken.

PostgreSQL database security vulnerability CVE-2026-6471 patch management

Summarised by CISO AI from Security Week. We link back to every original so you can read it yourself.