What is CVE-2026-18408?
This vulnerability involves untrusted data inclusion in PostgreSQL's pg_dump tool, allowing a malicious superuser on the origin server to inject arbitrary code. This code executes during restore-time as the client OS account running psql, via psql meta-command input expansion. Applying the fix for CVE-2025-8714 is recommended to mitigate the issue.
Azərbaycanca: Bu zəiflik PostgreSQL-in pg_dump alətində etibarsız məlumat daxil edilməsi ilə bağlıdır və əsas serverdəki superuser-ə müdaxilə etməyə imkan verir. Nəticədə, təcavüzkar psql vasitəsilə dump bərpa edilərkən istənilən kodu icra edə bilər. Təsirə məruz qalmamaq üçün CVE-2025-8714 üçün təqdim olunmuş yamağı tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-94; shared vendor: PostgreSQL
FAQ2
Which PostgreSQL tool does CVE-2026-18408 affect?
This vulnerability affects PostgreSQL's pg_dump tool.
What mitigation is recommended for CVE-2026-18408?
Applying the fix for CVE-2025-8714 is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.