Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-14680

PostgreSQL: type confusion through "internal" arguments executes arbitrary code

Technology

PostgreSQL

CVSS Score

8.8 / 10.0

Affected Versions

Before 18.6, 17.11, 16.15, 15.19 and 14.24 (supported versions only; 13 and older not assessed)

Upstream Fix

18.6; 17.11; 16.15; 15.19; 14.24

Published

August 13, 2026

OSSeva Coverage

Fixed upstream

Description

Type "internal" stands for a class of mutually incompatible data structures that are not meant to be reached from SQL. PostgreSQL intended to block SQL calls to functions taking that type, but the block had gaps, so any user could call them and run arbitrary code as the operating system user running the database. Scored 8.8 by PostgreSQL as the CNA. Fixed in 18.6, 17.11, 16.15, 15.19 and 14.24.

Upstream record: NVD · CVE.org

Is your PostgreSQL deployment affected?

If you're running Before 18.6, 17.11, 16.15, 15.19 and 14.24 (supported versions only; 13 and older not assessed), you need this patch. Book a discovery call to get covered.