PostgreSQL REFRESH PUBLICATION allows SQL injection via table name
Summary
| CVE | CVE-2026-6638 |
|---|---|
| State | PUBLISHED |
| Assigner | PostgreSQL |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-05-14 14:16:25 UTC |
| Updated | 2026-05-14 16:21:23 UTC |
| Description | SQL injection in PostgreSQL logical replication ALTER SUBSCRIPTION ... REFRESH PUBLICATION allows a subscriber table creator to execute arbitrary SQL with the subscription's publication-side credentials. The attack takes effect at the next REFRESH PUBLICATION. Within major versions 16, 17, and 18, minor versions before PostgreSQL 18.4, 17.10, and 16.14 are affected. Versions before PostgreSQL 16 are unaffected. |
Risk And Classification
Primary CVSS: v3.1 3.7 LOW from f86ef6dc-4d3a-42ad-8f28-e6d5547a5007
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N
Problem Types: CWE-89 | CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | f86ef6dc-4d3a-42ad-8f28-e6d5547a5007 | Secondary | 3.7 | LOW | CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N |
| 3.1 | CNA | CVSS | 3.7 | LOW | CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
HighPrivileges Required
LowUser Interaction
RequiredScope
UnchangedConfidentiality
LowIntegrity
LowAvailability
NoneCVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Na | PostgreSQL | affected 18 18.4 rpm | Not specified |
| CNA | Na | PostgreSQL | affected 17 17.10 rpm | Not specified |
| CNA | Na | PostgreSQL | affected 16 16.14 rpm | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.postgresql.org/support/security/CVE-2026-6638 | f86ef6dc-4d3a-42ad-8f28-e6d5547a5007 | www.postgresql.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: The PostgreSQL project thanks Pavel Kohout, Aisle Research for reporting this problem. (en)
There are currently no legacy QID mappings associated with this CVE.