Threat Intelligence

PostgreSQL Patches Decade-Old Flaw Allowing Code Execution via Replication Accounts

The Hacker News · 5 Sept 2026
Key Takeaway If your business runs PostgreSQL, update to the latest patched version immediately and review who holds replication-level database access.

PostgreSQL has released security updates fixing a long-standing vulnerability, tracked as CVE-2026-6471, that allows a database account with the REPLICATION attribute to execute arbitrary code as the operating system user running the database server. The flaw has existed since logical decoding was introduced in PostgreSQL 9.4 back in 2014, meaning it has gone unnoticed for roughly 12 years despite the software's wide use.

The issue carries a CVSS score of 7.2, reflecting a serious but not critical risk—exploitation requires an attacker to already hold an account with replication privileges, which limits the pool of potential attackers to insiders or those who have compromised a privileged account. Once that access is obtained, however, the flaw could allow full code execution on the underlying server, potentially leading to further compromise of connected systems.

Affected versions include all releases prior to PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24. Businesses running any of these versions should apply the latest updates as soon as possible, particularly if their database configuration grants replication access to multiple users or automated services.

PostgreSQL vulnerability database security patch management CVE-2026-6471

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.