{"api_version":"1","generated_at":"2026-08-22T17:47:28+00:00","cve":"CVE-2026-16238","urls":{"html":"https://cve.report/CVE-2026-16238","api":"https://cve.report/api/cve/CVE-2026-16238.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-16238","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-16238"},"summary":{"title":"PostgreSQL type confusion in pg_restore_attribute_stats() executes arbitrary code","description":"Type confusion in PostgreSQL pg_restore_attribute_stats() allows an object creator to execute arbitrary code as the operating system user running the database, via conflation of range and multirange values.  Within major version 18, minor versions before PostgreSQL 18.5 are affected.  Versions before PostgreSQL 18 are unaffected.","state":"PUBLISHED","assigner":"PostgreSQL","published_at":"2026-08-13 13:17:46","updated_at":"2026-08-19 14:59:58"},"problem_types":["CWE-843","CWE-843 Access of Resource Using Incompatible Type ('Type Confusion')"],"metrics":[{"version":"3.1","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","type":"Secondary","score":"8.8","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"8.8","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"baseScore":8.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://www.postgresql.org/support/security/CVE-2026-16238/","name":"https://www.postgresql.org/support/security/CVE-2026-16238/","refsource":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","tags":["Vendor Advisory"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-16238","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-16238","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"PostgreSQL","version":"affected 18 18.5 rpm","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[{"source":"CNA","title":"","value":"Revoke public EXECUTE permission on the function","time":"","lang":"en"}],"exploits":[],"credits":[{"source":"CNA","value":"The PostgreSQL project thanks Amy Burnett (OpenAI Codex Security) for reporting this problem.","lang":"en"}],"nvd_cpes":[{"cve_year":"2026","cve_id":"16238","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"postgresql","cpe5":"postgresql","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"16238","cve":"CVE-2026-16238","epss":"0.005900000","percentile":"0.454510000","score_date":"2026-08-18","updated_at":"2026-08-19 00:07:28"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-16238","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","timestamp":"2026-08-13T00:00:00+00:00","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-08-14T03:55:36.042Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"PostgreSQL","vendor":"n/a","versions":[{"lessThan":"18.5","status":"affected","version":"18","versionType":"rpm"}]}],"configurations":[{"lang":"en","value":"attacker has permission to create objects (temporary objects or non-temporary objects in at least one schema)"}],"credits":[{"lang":"en","value":"The PostgreSQL project thanks Amy Burnett (OpenAI Codex Security) for reporting this problem."}],"descriptions":[{"lang":"en","value":"Type confusion in PostgreSQL pg_restore_attribute_stats() allows an object creator to execute arbitrary code as the operating system user running the database, via conflation of range and multirange values.  Within major version 18, minor versions before PostgreSQL 18.5 are affected.  Versions before PostgreSQL 18 are unaffected."}],"metrics":[{"cvssV3_1":{"baseScore":8.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"format":"CVSS"}],"problemTypes":[{"descriptions":[{"cweId":"CWE-843","description":"Access of Resource Using Incompatible Type ('Type Confusion')","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-08-13T13:00:12.450Z","orgId":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","shortName":"PostgreSQL"},"references":[{"url":"https://www.postgresql.org/support/security/CVE-2026-16238/"}],"title":"PostgreSQL type confusion in pg_restore_attribute_stats() executes arbitrary code","workarounds":[{"lang":"en","value":"Revoke public EXECUTE permission on the function"}],"x_postgresql":{"component":"core server"}}},"cveMetadata":{"assignerOrgId":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","assignerShortName":"PostgreSQL","cveId":"CVE-2026-16238","datePublished":"2026-08-13T13:00:12.450Z","dateReserved":"2026-07-20T01:55:07.055Z","dateUpdated":"2026-08-14T03:55:36.042Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-13 13:17:46","lastModifiedDate":"2026-08-19 14:59:58","problem_types":["CWE-843","CWE-843 Access of Resource Using Incompatible Type ('Type Confusion')"],"metrics":{"cvssMetricV31":[{"source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-13T00:00:00+00:00","id":"CVE-2026-16238","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*","versionStartIncluding":"14.0","versionEndExcluding":"14.24","matchCriteriaId":"6BEE5714-C2EF-48DC-8613-C3EAA149E12E"},{"vulnerable":true,"criteria":"cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*","versionStartIncluding":"15.0","versionEndExcluding":"15.19","matchCriteriaId":"F433746A-733F-4ED0-9913-8AF69E0C8BF2"},{"vulnerable":true,"criteria":"cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*","versionStartIncluding":"16.0","versionEndExcluding":"16.15","matchCriteriaId":"1996B91F-E0B2-4A78-8788-E17EA68D179C"},{"vulnerable":true,"criteria":"cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*","versionStartIncluding":"17.0","versionEndExcluding":"17.11","matchCriteriaId":"3D04E642-71D7-4979-AA19-B9CCDEFD8C31"},{"vulnerable":true,"criteria":"cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*","versionStartIncluding":"18.0","versionEndExcluding":"18.5","matchCriteriaId":"8494F67B-673A-4E1F-8F40-D24DCC1F8DA4"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"16238","Ordinal":"1","Title":"PostgreSQL type confusion in pg_restore_attribute_stats() execut","CVE":"CVE-2026-16238","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"16238","Ordinal":"1","NoteData":"Type confusion in PostgreSQL pg_restore_attribute_stats() allows an object creator to execute arbitrary code as the operating system user running the database, via conflation of range and multirange values.  Within major version 18, minor versions before PostgreSQL 18.5 are affected.  Versions before PostgreSQL 18 are unaffected.","Type":"Description","Title":"PostgreSQL type confusion in pg_restore_attribute_stats() execut"}]}}}