What is CVE-2026-15741?
CVE-2026-15741 is an SQL injection vulnerability in PostgreSQL's EXTRACT() deparse process, allowing an object owner to execute arbitrary SQL commands as a superuser via a malicious object definition. It broadly affects expression deparse consumers like pg_dump, psql commands, and similar tools, requiring immediate application of security patches for affected versions.
Azərbaycanca: CVE-2026-15741 PostgreSQL-in EXTRACT() funksiyasının deparse əməliyyatında aşkarlanmış SQL injection zəifliyidir. Obyekt sahibi superuser səlahiyyətləri ilə ixtiyari SQL əmrləri icra edə bilər, bu da xüsusilə pg_dump, psql komandaları və oxşar vasitələrdə təhlükə yaradır. PostgreSQL-in təsirlənən versiyalarından istifadə edənlər dərhal təhlükəsizlik yeniləməsini tətbiq etməlidir.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
In which PostgreSQL function was CVE-2026-15741 discovered?
CVE-2026-15741 is an SQL injection vulnerability discovered in the deparse process of PostgreSQL's EXTRACT() function.
Which operations are particularly impacted by CVE-2026-15741?
The vulnerability broadly affects expression deparse consumers like pg_dump, psql commands, and similar tools.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.