CVE-2026-96883
Type confusion in AWS pgcollection allows remote code execution
CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th
pgcollection is an open source extension to PostgreSQL. A type confusion issue in AWS pgcollection 2.0.0 through 2.1.1 might allow an authenticated remote user to execute arbitrary code as the postgres operating system user via crafted SQL statements that rely on mismatched type metadata in collection value retrieval and array conversion functions. To remediate this issue, users should upgrade to version 2.1.2 or later.
| CWE | CWE-843 |
| Vendor | aws |
| Product | pgcollection |
| Published | Sep 24, 2026 |
| Last Updated | Sep 24, 2026 |
Stay Ahead of the Next One
Get instant alerts for aws pgcollection
Be the first to know when new high vulnerabilities affecting aws pgcollection are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
AWS / pgcollection
2.0.0 โค 2.1.1