CVE-2026-19633
Description
A flaw was found in PostgreSQL Anonymizer. This vulnerability allows unprivileged masked users to execute arbitrary code. By manipulating operators, domain casts, or view subqueries that contain untrusted expressions, an attacker can cause malicious code to run with elevated privileges within the extension's masking mechanisms. This could lead to a complete compromise of the affected system.
Statement
Red Hat Product Security has determined that this vulnerability does not affect any currently supported Red Hat product. This assessment may evolve based on further analysis and discovery. For more information about this vulnerability and the products it affects, please see the linked references.
Mitigation
If the PostgreSQL Anonymizer extension is not actively used, consider removing the associated package to eliminate the vulnerability. Removing the extension will prevent unprivileged masked users from exploiting this flaw. If the extension is required, ensure that only trusted expressions are processed and restrict access for unprivileged masked users as much as possible. Consult PostgreSQL documentation for proper extension management and security best practices.
Understanding the Weakness (CWE)
Confidentiality
Technical Impact: Read Application Data
Integrity
Technical Impact: Execute Unauthorized Code or Commands
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.