What is CVE-2026-14676?
CVE-2026-14676 is a heap buffer overflow vulnerability in PostgreSQL's pg_stat_statements extension. An authenticated query author can execute arbitrary code under the database's OS user privileges by sending crafted queries containing array constants. Users running PostgreSQL versions prior to 18.5 must apply the available update immediately.
Azərbaycanca: CVE-2026-14676, PostgreSQL-in pg_stat_statements genişlənməsində aşkarlanan heap buffer overflow zəifliyidir. Təsdiqlənmiş istifadəçi xüsusi hazırlanmış sorğular vasitəsilə verilənlər bazası prosesinin icra səlahiyyətləri ilə sistemdə ixtiyari kod icra edə bilər. PostgreSQL 18.5-dən əvvəlki versiyaları istifadə edənlər dərhal yeniləmə tətbiq etməlidir.
Related CVEs
link basis: same weakness class CWE-119; shared vendor: PostgreSQL
FAQ2
Which PostgreSQL component does CVE-2026-14676 affect?
This vulnerability is a heap buffer overflow issue in the pg_stat_statements extension of PostgreSQL.
What privileges can an attacker gain by exploiting this vulnerability?
An authenticated query author can execute arbitrary code under the database's OS user privileges.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.