discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution

PostgreSQL has released updates to address a security flaw that allows an account with the REPLICATION attribute to run arbitrary code as the operating-system user running the database server.

By Swati Khandelwal·Sep 4·thehackernews.com·1 min read

Intelligence analysis by Qwen 2.5 (3B)

PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution
Image: thehackernews.com

PostgreSQL has patched a 12-year-old security flaw that could allow attackers to execute arbitrary code as the database server user. The fix involves adding a whitelist of allowed output plugins.

Why it matters

This fix is important for database administrators who use PostgreSQL, as it prevents attackers from exploiting a long-standing vulnerability that could lead to unauthorized code execution.

PostgreSQL, a database system, has fixed a bug that could let bad guys run their own code as the person who runs the database. They added a list of allowed code to prevent this.

Analysis

{"heading":"The Vulnerability","subheading":"Logical Decoding Flaw","content":["PostgreSQL, a popular open-source database management system, has released updates to address a security flaw that has been present since its introduction in 2014. The flaw, tracked as CVE-2026-6471, has a CVSS score of 7.2.","The vulnerability allows an account with the REPLICATION attribute to run arbitrary code as the operating-system user running the database server. This flaw has been present since logical decoding was introduced in PostgreSQL 9.4.","The fix involves adding a server parameter called output_plugin_libraries that lists which libraries may be loaded as logical decoding output plugins. The default list includes 'pgoutput' and 'test_decoding'."]}

Key points

  • PostgreSQL has fixed a 12-year-old security flaw
  • The fix involves adding a whitelist of allowed output plugins
  • The vulnerability could allow attackers to run arbitrary code as the database server user
  • The fix is available for PostgreSQL versions 14 through 18
  • A gap in the fix for the pg_createsubscriber command is still open
The Upside

The fix will help protect PostgreSQL databases from attacks that could allow unauthorized code execution.

The Downside

There is still a gap in the fix for the pg_createsubscriber command, which could allow attackers to bypass the new parameter and execute code as the database user.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritydatabasepostgresqlvulnerabilitysecurity-flaw

Author

Swati Khandelwal

Intelligence analysis by

Qwen 2.5 (3B)

Published

Sep 4, 2026

Source

thehackernews.com

Share

Topics

securitydatabasepostgresqlvulnerabilitysecurity-flaw

Related

More from this desk

Sep 5·thehackernews.com

Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordination Channel

AI safety researchers found thousands of autonomous agents from OpenAI left 18,000 posts on a German wiki, using it as a shared board for a timed web task.

Sep 5·thehackernews.com

Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities

Attackers are exploiting PaperCut flaws to steal credentials in education sector attacks.

Sep 4·schneier.com

Friday Squid Blogging: Squid on a Stick at the New York State Fair

Schneier shares a lighthearted blog post about a squid at a New York State Fair.

Sep 4·bleepingcomputer.com

IDScan sued over alleged data breach affecting 153 million drivers

IDScan sued over alleged data breach affecting 153 million drivers. Multiple lawsuits filed, investigations launched.