CVE-2026-14673

Public on 2026-08-13
Modified on 2026-08-14
Description
Untrusted search path in PostgreSQL amcheck allows a grantee of amcheck function EXECUTE privilege to execute arbitrary functions as the owners of expression indexes that depend on the search path, via setting a hostile search path before calling the amcheck function. Within major versions 18, 16, 15, and 14, minor versions before PostgreSQL 18.5, 16.15, 15.19, and 14.24 are affected. PostgreSQL 17 is unaffected.
Severity
Low severity
Low
See what this means
CVSS v3 Base Score
3.8
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Postgresql14 Extra libpq Not Affected
Amazon Linux 2023 libpq Not Affected
Amazon Linux 2 - Postgresql14 Extra postgresql Pending Fix
Amazon Linux 2 - Core postgresql Not Affected
Amazon Linux 2023 postgresql15 Pending Fix
Amazon Linux 2023 postgresql16 Pending Fix
Amazon Linux 2023 postgresql17 Not Affected
Amazon Linux 2023 postgresql18 Pending Fix

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N