Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-16239

PostgreSQL: type confusion in the cursor and portal lifecycle executes arbitrary code

Technology

PostgreSQL

CVSS Score

8.8 / 10.0

Affected Versions

Before 18.6, 17.11, 16.15, 15.19 and 14.24 (supported versions only; 13 and older not assessed)

Upstream Fix

18.6; 17.11; 16.15; 15.19; 14.24

Published

August 13, 2026

OSSeva Coverage

Fixed upstream

Description

Re-creating a cursor or other portal with different types caused type confusion that let a database user run arbitrary code as the operating system user running the database. Scored 8.8 by PostgreSQL as the CNA. Fixed in 18.6, 17.11, 16.15, 15.19 and 14.24.

Upstream record: NVD · CVE.org

Is your PostgreSQL deployment affected?

If you're running Before 18.6, 17.11, 16.15, 15.19 and 14.24 (supported versions only; 13 and older not assessed), you need this patch. Book a discovery call to get covered.