CVE-2026-14681
Description
A flaw was found in PostgreSQL. Improper enforcement of message integrity in PostgreSQL's GSSAPI (Generic Security Service Application Program Interface) support allows a user to negotiate GSSAPI contrary to pg_hba.conf rules by initiating a direct TLS (Transport Layer Security) connection. This enables the connection to proceed with only TLS encryption, even when GSSAPI is required. If the TLS settings are less secure than the GSSAPI settings, the connection may operate with reduced protection, potentially leading to information disclosure or integrity compromise.
Statement
This Moderate severity flaw in PostgreSQL's GSSAPI support allows a remote, authenticated attacker with low privileges to bypass pg_hba.conf rules requiring GSSAPI encryption. By initiating a direct TLS connection, the attacker can force a less secure connection if TLS settings are more permissive, potentially compromising data integrity and confidentiality. The high attack complexity reduces the overall risk.
Mitigation
To mitigate the risk associated with this flaw, restrict network access to the PostgreSQL server to only trusted hosts and networks. This reduces the attack surface and limits the ability of unauthorized users to establish connections that could bypass GSSAPI enforcement via direct TLS.
*Warning:* Restricting network access may impact legitimate client connections if not configured carefully. Changes to firewall rules or network configurations may require a service reload or restart to take effect.
Common Vulnerability Scoring System (CVSS) Score Details
Info alert:Important note
CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).
The following CVSS metrics and score provided are preliminary and subject to review.
CVSS v3 Score Breakdown
| Red Hat | NVD | cve.org | |
|---|---|---|---|
| Base Score | 4.2 | N/A | 4.2 |
| Attack Vector | Network | N/A | Network |
| Attack Complexity | High | N/A | High |
| Privileges Required | Low | N/A | Low |
| User Interaction | None | N/A | None |
| Scope | Unchanged | N/A | Unchanged |
| Confidentiality | Low | N/A | Low |
| Integrity Impact | Low | N/A | Low |
| Availability Impact | None | N/A | None |
Vector
Red Hat: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
cve.org: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Understanding the Weakness (CWE)
Integrity,Confidentiality
Technical Impact: Gain Privileges or Assume Identity
If an attackers can spoof the endpoint, the attacker gains all the privileges that were intended for the original endpoint.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.