Arbitrary Code Execution Vulnerability in PostgreSQL Anonymizer by Dalibo
CVE-2026-19633

8.8HIGH

Key Information:

Vendor

Dalibo

Vendor
CVE Published:
6 September 2026

What is CVE-2026-19633?

The PostgreSQL Anonymizer extension includes a vulnerability that could enable unprivileged masked users to execute arbitrary code. This issue arises when operators, domain casts, or view subqueries containing untrusted expressions are evaluated within the context of the extension's masking mechanisms. If exploited, this vulnerability could allow attackers to run malicious code with elevated privileges. The issue has been addressed in PostgreSQL Anonymizer version 3.1.4 and higher.

Affected Version(s)

PostgreSQL Anonymizer 1 < 3.1.4

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

The PostgreSQL Anonymizer project thanks user Sarath Kumar for reporting this problem.
.