What is CVE-2026-49004?
The built-in PostgreSQL service on the mobile device has misconfiguration flaws and command injection vulnerabilities. Running with root privileges and protected by weak credentials, it permits local command execution via the COPY FROM PROGRAM syntax. It is recommended to disable the service, update credentials, or apply the manufacturer's security patch.
Azərbaycanca: Mobil cihazda quraşdırılmış PostgreSQL xidməti zəif konfiqurasiya və command injection zəifliklərinə malikdir. Bu xidmət root imtiyazları ilə işləyir, zəif şifrələrlə qorunur və COPY FROM PROGRAM sintaksisi vasitəsilə yerli əmrlərin icrasına imkan yaradır. Bu problemi aradan qaldırmaq üçün xidməti söndürmək, giriş məlumatlarını yeniləmək və ya istehsalçı tərəfindən təqdim olunan təhlükəsizlik yeniləməsini tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-77
FAQ1
Through which syntax does CVE-2026-49004 allow local command execution?
CVE-2026-49004 allows local command execution through the COPY FROM PROGRAM syntax in the PostgreSQL service.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.