CVE-2026-2004

Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object creator to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*

History

20 Feb 2026, 19:53

Type Values Removed Values Added
CPE cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*
First Time Postgresql
Postgresql postgresql
References () https://www.postgresql.org/support/security/CVE-2026-2004/ - () https://www.postgresql.org/support/security/CVE-2026-2004/ - Vendor Advisory

12 Feb 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-12 14:16

Updated : 2026-02-20 19:53


NVD link : CVE-2026-2004

Mitre link : CVE-2026-2004

CVE.ORG link : CVE-2026-2004


JSON object : View

Products Affected

postgresql

  • postgresql
CWE
CWE-1287

Improper Validation of Specified Type of Input