PostgreSQL Superuser Escalation in pglogical by EnterpriseDB
CVE-2026-50737

9CRITICAL

Key Information:

Status
Vendor
CVE Published:
28 July 2026

What is CVE-2026-50737?

This vulnerability in pglogical allows an attacker to escalate privileges to superuser level on PostgreSQL installations. By manipulating replicated changes for rows missing certain columns, attackers can execute functions with superuser privileges on the subscriber system. This occurs because the apply worker operates with elevated privileges during these operations. Successfully exploiting this vulnerability typically requires the ability to direct subscriptions to a controlled endpoint, a capability usually restricted to superusers. This poses significant security risks, particularly in managed deployments where non-superuser roles can create subscriptions.

Affected Version(s)

pglogical 2

References

CVSS V4

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mehmet Ince (@mdisec)
.