logo

PoC Exploit Publicly Disclosed: 20-Year-Old PostgreSQL pgcrypto Flaw (CVE-2026-2005) Grants Full Superuser RCE

ID: 588ab2e8-2fc5-5695-8bae-b2c0fde57209

STIX ID: report--588ab2e8-2fc5-5695-8bae-b2c0fde57209

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-05-19

Date Updated: 2026-05-22

Author: Ddos

...
...

A critical heap buffer overflow (CVE-2026-2005) in PostgreSQL's native pgcrypto extension—present since 2005—was publicly disclosed with a fully functional proof-of-concept that can be triggered by users with CREATE privileges to gain bootstrap superuser privileges via pgp_pub_decrypt_bytea(); upstream patches were released in February 2026 and administrators are urged to apply specified patched baselines or adopt immediate network and credential mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.