What is CVE-2026-6470?
CVE-2026-6470 is a missing authorization vulnerability in PostgreSQL DDL commands. An object creator can cause denial of service against ALTER and DROP operations by creating a dependency on the type. Affected systems should apply the relevant security patches immediately.
Azərbaycanca: CVE-2026-6470, PostgreSQL-in DDL əmrlərində çatışmayan avtorizasiya zəifliyidir. Obyekt yaradan şəxs ALTER və DROP əməliyyatlarına qarşı denial of service yarada bilər. Təsirə məruz qalan sistemlərdə dərhal müvafiq yamaqlar tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
What type of commands does the CVE-2026-6470 vulnerability affect in PostgreSQL?
This vulnerability affects DDL (Data Definition Language) commands in PostgreSQL.
What type of attack can a threat actor perform by exploiting CVE-2026-6470?
A threat actor can cause a denial of service (DoS) attack against ALTER and DROP operations by creating an object.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.