CVE-2026-19633

Description

A flaw was found in PostgreSQL Anonymizer. This vulnerability allows unprivileged masked users to execute arbitrary code. By manipulating operators, domain casts, or view subqueries that contain untrusted expressions, an attacker can cause malicious code to run with elevated privileges within the extension's masking mechanisms. This could lead to a complete compromise of the affected system.

Statement

Red Hat Product Security has determined that this vulnerability does not affect any currently supported Red Hat product. This assessment may evolve based on further analysis and discovery. For more information about this vulnerability and the products it affects, please see the linked references.

Mitigation

If the PostgreSQL Anonymizer extension is not actively used, consider removing the associated package to eliminate the vulnerability. Removing the extension will prevent unprivileged masked users from exploiting this flaw. If the extension is required, ensure that only trusted expressions are processed and restrict access for unprivileged masked users as much as possible. Consult PostgreSQL documentation for proper extension management and security best practices.

Understanding the Weakness (CWE)

Confidentiality

Technical Impact: Read Application Data

Integrity

Technical Impact: Execute Unauthorized Code or Commands

Frequently Asked Questions

Want to get errata notifications? Sign up here.