logo

PoC Exploit Released for 20-Year Old PostgreSQL RCE Vulnerability

ID: 3ad90be0-7ab3-596c-9a2f-2441cf438cfd

STIX ID: report--3ad90be0-7ab3-596c-9a2f-2441cf438cfd

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-05-20

Date Updated: 2026-05-20

Author: Abinaya

...
...

A public proof-of-concept for CVE-2026-2005 — a critical heap-based buffer overflow in PostgreSQL's pgcrypto extension — has been released, demonstrating an exploitation chain from memory corruption to arbitrary memory read/write, escalation to the PostgreSQL superuser (by modifying CurrentUserId), and execution of OS commands (e.g., via COPY FROM PROGRAM); exploitation depends on specific vulnerable PostgreSQL builds and uses Python tooling (psycopg2, pwntools), but the PoC significantly lowers the barrier for attackers against unpatched systems with pgcrypto enabled.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.