Arbitrary Code Execution Vulnerability in PostgreSQL Anonymizer by Dalibo
CVE-2026-19633
8.8HIGH
What is CVE-2026-19633?
The PostgreSQL Anonymizer extension includes a vulnerability that could enable unprivileged masked users to execute arbitrary code. This issue arises when operators, domain casts, or view subqueries containing untrusted expressions are evaluated within the context of the extension's masking mechanisms. If exploited, this vulnerability could allow attackers to run malicious code with elevated privileges. The issue has been addressed in PostgreSQL Anonymizer version 3.1.4 and higher.
Affected Version(s)
PostgreSQL Anonymizer 1 < 3.1.4
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
The PostgreSQL Anonymizer project thanks user Sarath Kumar for reporting this problem.
