CVE-2026-2004: PostgreSQL vulnerability analysis and mitigation
Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object creator to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.
Source: NVD
Related PostgreSQL vulnerabilities:
CVE ID
Severity
Score
Technologies
Component name
CISA KEV exploit
Has fix
Published date
CVE-2026-2006
HIGH
8.8
PostgreSQL
postgresql17-devel
No
Yes
Feb 12, 2026
CVE-2026-2005
HIGH
8.8
PostgreSQL
postgresql18-server
No
Yes
Feb 12, 2026
CVE-2026-2004
HIGH
8.8
PostgreSQL
postgresql:12::postgresql-server-devel
No
Yes
Feb 12, 2026
CVE-2026-2007
HIGH
8.2
PostgreSQL
libpq5
No
Yes
Feb 12, 2026
CVE-2026-3172
HIGH
8.1
PostgreSQL
postgresql18-pgvector
No
Yes
Feb 25, 2026
Free Vulnerability Assessment
Benchmark your Cloud Security Posture
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.