CVE-2026-2004HIGH 8.8EPSS p52.5%
CVE-2026-2004CVE-2026-2004
postgresql / postgresql
Description
Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object creator to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.
Scoring
| CVSS 3.1 | 8.8 (HIGH) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 0.78% probability of exploitation · percentile 52.5% · 2026-08-03T12:00:16Z |
| Published | 2026-02-12 |
| Last modified | 2026-07-15 |
Underlying weaknesses· 1
References
1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Improper Validation of Specified Type of Inputcwe-1287 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.