CVE-2026-6476
Published: 14 May 2026
Summary
CVE-2026-6476 is a high-severity SQL Injection (CWE-89) vulnerability in Postgresql (inferred from references). Its CVSS base score is 7.2 (High).
Operationally, it is not currently listed in the CISA KEV catalog.
Threat & Defense Details
Likely Mitigating ControlsAI
Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.
NVD Description
SQL injection in PostgreSQL pg_createsubscriber allows an attacker with pg_create_subscription rights to execute arbitrary SQL as a superuser. The attack takes effect when pg_createsubscriber next runs. Within major versions 17 and 18, minor versions before PostgreSQL 18.4 and 17.10 are…
more
affected. Versions before PostgreSQL 17 are unaffected.
Deeper analysisAI
Automated synthesis unavailable for this CVE.
Details
- CWE(s)