CVE-2026-6471 (“PostGREShell”) is a CVSS 7.2 missing-authorization flaw in PostgreSQL logical decoding that lets a non-superuser account with the REPLICATION privilege provide an arbitrary filesystem path as an output-plugin name. PostgreSQL then loads the selected shared library via dlopen() and executes it as the postgres operating-system user, enabling database-server takeover.
The vulnerability reportedly existed since PostgreSQL 9.4 and affects releases through PostgreSQL 18 before remediation. Exploitation can yield operating-system command execution, permanent PostgreSQL superuser escalation, access across databases, accessible private-key theft, and persistent backdoors. PostgreSQL fixed the issue in versions 18.6, 17.11, 16.15, 15.19, and 14.24; organizations should update affected deployments and review or remove unnecessary REPLICATION privileges.

Get the actors, campaigns, and ATT&CK mapping behind it.
4 events from the most recent confirmed update back to the earliest known activity.
PostgreSQL 13 reached end of life and no longer receives upstream security fixes. Consequently, PostgreSQL 13 deployments affected by CVE-2026-6471 do not receive an upstream PostGREShell patch.
The missing-authorization flaw in PostgreSQL logical decoding, later designated CVE-2026-6471 (PostGREShell), was reportedly present from PostgreSQL 9.4 in 2014.
PostgreSQL addressed PostGREShell in versions 18.6, 17.11, 16.15, 15.19, and 14.24. The flaw affected releases from version 9.4 through affected builds prior to those fixed versions.
Cyera researchers identified and reported CVE-2026-6471, which allows a non-superuser with the REPLICATION attribute to supply a malicious logical-decoding plugin path and execute code as the PostgreSQL server operating-system user.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
8 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecryptika.com
Open sourcethecybersecguru.com
Open sourcescworld.com
Open sourcethehackernews.com
Open sourcesecurityaffairs.com
Open sourcesecurityweek.com
Open sourcecyera.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.