Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.4

CVE-2026-96883: AWS pgcollection can let logged‑in user run code

CVE-2026-96883 · published 3 days ago
Summary

The pgcollection add‑on for PostgreSQL versions 2.0.0 through 2.1.1 can be tricked by a signed‑in user into running any command as the database’s operating‑system account. This happens when specially crafted SQL statements confuse the way the add‑on handles data types. Update pgcollection to version 2.1.2 or newer to close the gap.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
Ecosystem VendorProductAffected versions
– aws pgcollection <= 2.1.1
Ubuntu:Pro:14.04:LTS canonical postgresql-9.3 All versions
Ubuntu:Pro:16.04:LTS canonical postgresql-9.5 All versions
Ubuntu:Pro:18.04:LTS canonical postgresql-10 All versions
Ubuntu:20.04:LTS canonical postgresql-12 All versions
Ubuntu:22.04:LTS canonical postgresql-14 All versions
Ubuntu:24.04:LTS canonical postgresql-16 All versions
Ubuntu:26.04:LTS canonical postgresql-18 All versions
Original advisory text
Type confusion in AWS pgcollection allows remote code execution
pgcollection is an open source extension to PostgreSQL. A type confusion issue in AWS pgcollection 2.0.0 through 2.1.1 might allow an authenticated remote user to execute arbitrary code as the postgres operating system user via crafted SQL statements that rely on mismatched type metadata in collection value retrieval and array conversion functions.



To remediate this issue, users should upgrade to version 2.1.2 or later.
Severity
9.4 Critical
CVSS 3.1: 8.8 (NVD)
CVSS 4.0: 8.7 (NVD)
Exploitation
EPSS <1%
Type
CWE-843Type Confusion
Timeline
Published24 Sep 2026
Updated27 Sep 2026
First seen24 Sep 2026
Track software like this
Free during beta