← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 4, 2026 · 15:20via The Hacker News

PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution

Brief

PostgreSQL has released updates to address a security flaw that allows an account with the REPLICATION attribute to run arbitrary code as the operating-system user running the database server.

The flaw, tracked as CVE-2026-6471 (CVSS score: 7. 2), has been present since logical decoding was introduced in PostgreSQL 9. 4 in 2014. Versions before PostgreSQL 18. 6, 17. 11, 16. 15, 15. 19, and 14. 24 are

Read more on The Hacker News