PostgreSQL Superuser Escalation in pglogical by EnterpriseDB
CVE-2026-50737
9CRITICAL
What is CVE-2026-50737?
This vulnerability in pglogical allows an attacker to escalate privileges to superuser level on PostgreSQL installations. By manipulating replicated changes for rows missing certain columns, attackers can execute functions with superuser privileges on the subscriber system. This occurs because the apply worker operates with elevated privileges during these operations. Successfully exploiting this vulnerability typically requires the ability to direct subscriptions to a controlled endpoint, a capability usually restricted to superusers. This poses significant security risks, particularly in managed deployments where non-superuser roles can create subscriptions.
Affected Version(s)
pglogical 2
