What is CVE-2026-14662?
An integer wraparound vulnerability in PostgreSQL's tsvector and tsquery functions allows an unprivileged database user to cause undersized allocation and out-of-bounds write via crafted large inputs. This may lead to arbitrary code execution as the OS user running the database. Apply updates immediately.
Azərbaycanca: PostgreSQL-də tsvector və tsquery funksiyalarında tam ədəd daşması zəifliyi aşkar edilib. Bu, imtiyazsız verilənlər bazası istifadəçisinə xüsusi hazırlanmış böyük girişlər göndərərək yaddaş sərhədlərini aşmasına və verilənlər bazasını işlədən ƏS istifadəçisi kimi ixtiyari kod icra etməsinə imkan verir. Dərhal PostgreSQL yeniləmələrini tətbiq edin.
Related CVEs
link basis: same weakness class CWE-190; shared vendor: PostgreSQL
FAQ2
Who can exploit the CVE-2026-14662 vulnerability in PostgreSQL?
An unprivileged database user can exploit this vulnerability.
What can happen if CVE-2026-14662 is successfully exploited?
It may lead to arbitrary code execution as the OS user running the database.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.