What is CVE-2026-14673?
CVE-2026-14673 is an untrusted search path vulnerability in PostgreSQL's amcheck module. It allows a user with EXECUTE privilege on the amcheck function to execute arbitrary functions as the owners of expression indexes by setting a hostile search path. This primarily affects major versions 18 and 16, and immediate patching is recommended.
Azərbaycanca: CVE-2026-14673 PostgreSQL-in amcheck modulunda etibarsız axtarış yolu zəifliyidir. Bu, amcheck funksiyasını icra etmək imtiyazı olan istifadəçilərə, zərərli axtarış yolu təyin edərək expression indeks sahibləri adından ixtiyari funksiyalar icra etməyə imkan verir. Əsasən 18 və 16-cı versiyalara təsir edir, dərhal yeniləmə tövsiyə olunur.
Related CVEs
link basis: shared vendor: PostgreSQL
FAQ2
In which module of PostgreSQL was the CVE-2026-14673 vulnerability discovered?
The vulnerability was discovered in the amcheck module of PostgreSQL.
Which major versions of PostgreSQL are affected by this vulnerability?
CVE-2026-14673 primarily affects major versions 18 and 16 of PostgreSQL.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.