Type Confusion Vulnerability in PostgreSQL Affects Multiple Versions
CVE-2026-16239

8.8HIGH

Key Information:

Vendor

PostgreSQL

Vendor
CVE Published:
13 August 2026

What is CVE-2026-16239?

A vulnerability in the PostgreSQL database system allows attackers to exploit type confusion during the lifecycle of 'portal' and cursor operations. This flaw enables unauthorized users to execute arbitrary code with the privileges of the database process, which could lead to severe security risks, including data breaches. The issue impacts several previous versions of PostgreSQL before the fixes implemented in their recent releases. Prompt upgrading to the patched versions is recommended to mitigate this risk.

Affected Version(s)

PostgreSQL 18 < 18.5

PostgreSQL 17 < 17.11

PostgreSQL 16 < 16.15

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

The PostgreSQL project thanks Ben Morris (Claude and Anthropic Research) for reporting this problem.
.