CVE-2026-6469Postgresql · Postgresql
Vulnerability data via NVD (ingested)
Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reassigns ownership of dependent statistics objects to the current user. This wrongly allows the table owner to run DROP STATISTICS and ALTER STATISTICS via this improper ownership. It wrongly denies those commands to the prior statistics object owner. DROP TABLE remains able to remove statistics objects, so this exploit achieves nothing in many ownership arrangements. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-6469product:"Postgresql Postgresql"http.html:"Postgresql"More intel sources (5)
vuln:CVE-2026-6469vulnerabilities.cve_id: CVE-2026-6469CVE-2026-6469CVE-2026-6469"CVE-2026-6469" exploit -site:nvd.nist.gov