What is CVE-2026-50736?
The CVE-2026-50736 vulnerability in the pglogical queue mechanism allows out-of-band commands, such as replicated DDL, sent from a publisher to a subscriber to be executed at the superuser privilege level on the subscriber. This could allow an unauthorized party to gain full control of the subscriber database by sending malicious commands. Affected systems should immediately update pglogical or temporarily halt replication.
Azərbaycanca: pglogical növbə mexanizmində aşkar edilmiş CVE-2026-50736 zəifliyi, nəşrçidən abunəçiyə ötürülən out-of-band əmrlərin (məsələn, replikasiya olunmuş DDL) abunəçi tərəfdə superuser səviyyəsində icra edilməsinə imkan verir. Bu, icazəsi olmayan tərəfin zərərli əmrlər göndərərək abunəçi verilənlər bazasında tam nəzarəti ələ keçirə bilməsi ilə nəticələnə bilər. Təsirə məruz qalan sistemlərdə dərhal pglogical yenilənməli və ya müvəqqəti olaraq replikasiya dayandırılmalıdır.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
In which component of pglogical was CVE-2026-50736 discovered?
CVE-2026-50736 was discovered in the queue mechanism of pglogical.
How can this vulnerability impact the subscriber database?
Due to the vulnerability, out-of-band commands sent from the publisher can be executed at the superuser privilege level on the subscriber, potentially allowing an unauthorized party to gain full control of the database.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.