CVE-2026-14673
PostgreSQL amcheck does not clear untrusted search path
CVSS Score
3.8
EPSS Score
0.0%
EPSS Percentile
0th
Untrusted search path in PostgreSQL amcheck allows a grantee of amcheck function EXECUTE privilege to execute arbitrary functions as the owners of expression indexes that depend on the search path, via setting a hostile search path before calling the amcheck function. Within major versions 18, 16, 15, and 14, minor versions before PostgreSQL 18.5, 16.15, 15.19, and 14.24 are affected. PostgreSQL 17 is unaffected.
| CWE | CWE-426 |
| Vendor | n/a |
| Product | postgresql |
| Ecosystems | |
| Industries | Technology |
| Published | Aug 13, 2026 |
Stay Ahead of the Next One
Get instant alerts for n/a postgresql
Be the first to know when new low vulnerabilities affecting n/a postgresql are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
n/a / PostgreSQL
18 < 18.5 16 < 16.15 15 < 15.19 0 < 14.24
References
Credits
The PostgreSQL project thanks ็่ทๆ and Jacob Brazeal for reporting this problem.