SQL Injection Vulnerability in PostgreSQL Anonymizer by Dalibo
CVE-2026-19634

6.4MEDIUM

Key Information:

Vendor

Dalibo

Vendor
CVE Published:
6 September 2026

What is CVE-2026-19634?

The PostgreSQL Anonymizer features a SQL injection vulnerability within its import functions that can be exploited by malicious users. By crafting a specially formatted JSON document with specific object names, a superuser executing the functions anon.import_database_rules() or anon.import_roles_rules() could inadvertently execute harmful code with superuser privileges. This vulnerabilities risks exposing sensitive data and undermining database integrity. The issue has been addressed in PostgreSQL Anonymizer version 3.1.4 and later.

Affected Version(s)

PostgreSQL Anonymizer 1 < 3.1.4

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

The PostgreSQL Anonymizer project thanks user Sarath Kumar for reporting this problem.
.