Privilege Escalation Vulnerability in PostgreSQL Anonymizer by Dalibo
CVE-2026-83534

6.4MEDIUM

Key Information:

Vendor

Dalibo

Vendor
CVE Published:
6 September 2026

What is CVE-2026-83534?

A security flaw exists in the anon.anonymize_database_parallel() function of PostgreSQL Anonymizer, permitting the table owner to execute arbitrary code with superuser privileges. This vulnerability poses a significant risk as it could lead to unauthorized access and control over the database environment, potentially compromising sensitive data. Users are urged to upgrade to PostgreSQL Anonymizer version 3.2.0 or later to mitigate this issue.

Affected Version(s)

PostgreSQL Anonymizer 1 < 3.2.0

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

The PostgreSQL Anonymizer project thanks Alexander Kukushkin for reporting this problem.
.