What is CVE-2026-14672?
CVE-2026-14672 is an observable response discrepancy in PostgreSQL's SCRAM authentication. It allows an unauthenticated user to probe for the existence of a user by observing the SCRAM iteration count, provided the targeted user has a non-default scram_iterations value. Affected systems should apply security patches promptly to prevent username enumeration.
Azərbaycanca: CVE-2026-14672 PostgreSQL-in SCRAM autentifikasiyasında müşahidə olunan cavab uyğunsuzluğudur. Bu boşluq autentifikasiya olunmamış şəxsə hədəf istifadəçinin mövcudluğunu təyin etməyə imkan verir, əgər həmin istifadəçi qeyri-standart scram_iterations dəyərinə malikdirsə. Təsirlənən sistemlərdə istifadəçi adlarının sızmasının qarşısını almaq üçün dərhal təhlükəsizlik yeniləmələri tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
Which PostgreSQL authentication mechanism is affected by CVE-2026-14672?
This vulnerability affects PostgreSQL's SCRAM authentication.
What condition must the target user meet for CVE-2026-14672 to be exploited?
The targeted user must have a non-default scram_iterations value.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.