PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to execute arbitrary code by abusing operators, domain casts, or view subqueries that carry untrusted expressions. When these objects are evaluated in the context of the extension’s masking mechanisms, the malicious code can run with elevated privileges. The issue is fixed in PostgreSQL Anonymizer 3.1.4 and later versions
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://gitlab.com/dalibo/postgresql_anonymizer/-/issues/665 |
|
History
Tue, 08 Sep 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 06 Sep 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dalibo
Dalibo postgresql Anonymizer |
|
| Vendors & Products |
Dalibo
Dalibo postgresql Anonymizer |
Sun, 06 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to execute arbitrary code by abusing operators, domain casts, or view subqueries that carry untrusted expressions. When these objects are evaluated in the context of the extension’s masking mechanisms, the malicious code can run with elevated privileges. The issue is fixed in PostgreSQL Anonymizer 3.1.4 and later versions | |
| Title | PostgreSQL Anonymizer: unprivileged masked users can execute code via operators, domain casts and view subqueries | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: PostgreSQL
Published: 2026-09-06T15:25:32.533Z
Updated: 2026-09-09T04:26:01.195Z
Reserved: 2026-08-12T16:09:08.888Z
Link: CVE-2026-19633
Updated: 2026-09-08T10:33:42.789Z
Status : Awaiting Analysis
Published: 2026-09-06T16:16:49.583
Modified: 2026-09-09T05:17:19.990
Link: CVE-2026-19633
No data.