BIT-postgresql-2026-6475

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/postgresql/BIT-postgresql-2026-6475.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-postgresql-2026-6475
Aliases
  • CVE-2026-6475
Published
2026-05-18T05:53:02.016Z
Modified
2026-05-18T08:02:28.674686Z
Summary
PostgreSQL pg_basebackup and pg_rewind can overwrite unrelated files of origin superuser choice
Details

Symlink following in PostgreSQL pgbasebackup plain format and in pgrewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like sharedpreloadlibraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

Database specific
{
    "cpes": [
        "cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*"
    ],
    "severity": "High"
}
References

Affected packages

Bitnami / postgresql

Package

Name
postgresql
Purl
pkg:bitnami/postgresql

Severity

  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
14.23.0
Introduced
15.0.0
Fixed
15.18.0
Introduced
16.0.0
Fixed
16.14.0
Introduced
17.0.0
Fixed
17.10.0
Introduced
18.0.0
Fixed
18.4.0

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/postgresql/BIT-postgresql-2026-6475.json"