Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.4
CVE-2026-96883: AWS pgcollection can let logged‑in user run code
CVE-2026-96883 · published 3 days ago
Summary
The pgcollection add‑on for PostgreSQL versions 2.0.0 through 2.1.1 can be tricked by a signed‑in user into running any command as the database’s operating‑system account. This happens when specially crafted SQL statements confuse the way the add‑on handles data types. Update pgcollection to version 2.1.2 or newer to close the gap.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | aws | pgcollection | <= 2.1.1 |
| Ubuntu:Pro:14.04:LTS | canonical | postgresql-9.3 | All versions |
| Ubuntu:Pro:16.04:LTS | canonical | postgresql-9.5 | All versions |
| Ubuntu:Pro:18.04:LTS | canonical | postgresql-10 | All versions |
| Ubuntu:20.04:LTS | canonical | postgresql-12 | All versions |
| Ubuntu:22.04:LTS | canonical | postgresql-14 | All versions |
| Ubuntu:24.04:LTS | canonical | postgresql-16 | All versions |
| Ubuntu:26.04:LTS | canonical | postgresql-18 | All versions |
Original advisory text
Type confusion in AWS pgcollection allows remote code execution
pgcollection is an open source extension to PostgreSQL. A type confusion issue in AWS pgcollection 2.0.0 through 2.1.1 might allow an authenticated remote user to execute arbitrary code as the postgres operating system user via crafted SQL statements that rely on mismatched type metadata in collection value retrieval and array conversion functions.
To remediate this issue, users should upgrade to version 2.1.2 or later.
To remediate this issue, users should upgrade to version 2.1.2 or later.
References
- https://aws.amazon.com/security/security-bulletins/2026-118-aws/ Vendor Advisory
- https://github.com/aws/pgcollection/releases/tag/v2.1.2 Patch
- https://github.com/aws/pgcollection/security/advisories/GHSA-g539-cj32-hv6r Vendor Advisory
- https://ubuntu.com/security/CVE-2026-96883 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-96883 Third Party Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/96xxx/CVE-2026-96883... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-96883 Vendor Advisory
Severity
9.4
Critical
CVSS 3.1: 8.8 (NVD)
CVSS 4.0: 8.7 (NVD)
Exploitation
EPSS <1%
Type
CWE-843Type Confusion
Timeline
Published24 Sep 2026
Updated27 Sep 2026
First seen24 Sep 2026
Sources
CVE-2026-96883 · NVD
CVE-2026-96883 · MITRE
UBUNTU-CVE-2026-96883 · OSV
CVE-2026-96883 · OSV
GHSA-g539-cj32-hv6r · GHSA
Track software like this
Free during beta