What is CVE-2026-14671?
A type confusion vulnerability exists in PostgreSQL's "refint" module. It allows an object creator to execute arbitrary code as the operating system user running the database. The fix emerged from a non-security bug report and was added to the Git repository with the subject "refint: Remove plan cache."
Azərbaycanca: PostgreSQL-in "refint" modulunda tip qarışıqlığı (type confusion) zəifliyi aşkarlanıb. Obyekt yaradan şəxs verilənlər bazasını işlədən əməliyyat sistemi istifadəçisi kimi ixtiyari kod icra edə bilər. Təhlükəsizlik məqsədli olmayan bir səhv hesabatı nəticəsində düzəliş "refint: Remove plan cache." mövzusu ilə Git repozitoriyasına əlavə olunub.
FAQ2
Which PostgreSQL module is affected by CVE-2026-14671?
This vulnerability is a type confusion issue discovered in PostgreSQL's "refint" module.
What can an attacker achieve by exploiting CVE-2026-14671?
An object creator can execute arbitrary code as the operating system user running the database.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.