Description
Incomplete tracking in PostgreSQL of changes to role membership, role attributes, and database ownership allows a query to continue using cached row-level security policies after those changes require a different policy, via plan reuse. Stale policies continue until some other event invalidates the cache or connection termination ends the session. This permits a user to complete reads and modifications that were recently permitted but now forbidden. An attacker must tailor an attack to a particular application's pattern of privilege removal and role-specific row security policies. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.
Published: 2026-08-13
Score: 4.2 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from PostgreSQL's incomplete tracking of changes to role membership, role attributes, and database ownership. When a role change occurs, the server continues to reuse cached row‑level security policies from a previous query plan, even if those policies are no longer valid. This stale policy allows a user who has recently lost privileges to read and modify rows that should now be protected.

Affected Systems

PostgreSQL instances running any version prior to 18.5, 17.11, 16.15, 15.19, or 14.24 are affected.

Risk and Exploitability

The CVSS score of 4.2 indicates a moderate impact. The EPSS score is unavailable and the vulnerability is not listed in the CISA KEV catalog. An attacker must first alter role or ownership settings that change row‑level security requirements and then execute a query that the database reuses the old plan for. This attack path requires knowledge of the application’s privilege model and is therefore less likely to be widely exploitable, but it remains a concern for environments that rely heavily on role‑specific row security.

Generated by OpenCVE AI on August 13, 2026 at 14:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade PostgreSQL to version 18.5 or later, 17.11 or later, 16.15 or later, 15.19 or later, or 14.24 or later.
  • Restart the database or terminate user sessions immediately after any role, ownership, or attribute changes to force cache invalidation.
  • Implement monitoring and auditing of row‑level security policy usage to detect unexpected data access patterns.

Generated by OpenCVE AI on August 13, 2026 at 14:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Postgresql
Postgresql postgresql
Vendors & Products Postgresql
Postgresql postgresql

Thu, 13 Aug 2026 13:15:00 +0000

Type Values Removed Values Added
Description Incomplete tracking in PostgreSQL of changes to role membership, role attributes, and database ownership allows a query to continue using cached row-level security policies after those changes require a different policy, via plan reuse. Stale policies continue until some other event invalidates the cache or connection termination ends the session. This permits a user to complete reads and modifications that were recently permitted but now forbidden. An attacker must tailor an attack to a particular application's pattern of privilege removal and role-specific row security policies. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.
Title PostgreSQL row security caching disregards role modifications
Weaknesses CWE-1250
References
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Postgresql Postgresql
cve-icon MITRE

Status: PUBLISHED

Assigner: PostgreSQL

Published:

Updated: 2026-08-13T15:34:56.928Z

Reserved: 2026-07-03T20:28:10.229Z

Link: CVE-2026-14666

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-13T13:17:43.993

Modified: 2026-08-13T13:17:43.993

Link: CVE-2026-14666

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T15:00:04Z

Weaknesses
  • CWE-1250

    Improper Preservation of Consistency Between Independent Representations of Shared State