PoC Exploit Publicly Disclosed: 20-Year-Old PostgreSQL pgcrypto Flaw (CVE-2026-2005) Grants Full Superuser RCE
ID: 588ab2e8-2fc5-5695-8bae-b2c0fde57209
STIX ID: report--588ab2e8-2fc5-5695-8bae-b2c0fde57209
Feed Name: securityonline.info
Threat Score
A critical heap buffer overflow (CVE-2026-2005) in PostgreSQL's native pgcrypto extension—present since 2005—was publicly disclosed with a fully functional proof-of-concept that can be triggered by users with CREATE privileges to gain bootstrap superuser privileges via pgp_pub_decrypt_bytea(); upstream patches were released in February 2026 and administrators are urged to apply specified patched baselines or adopt immediate network and credential mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
