Skip to finding
important · Database privilege

A PostgreSQL replication role can load native code and establish persistent database-superuser control.

Affects

PostgreSQL database servers on Windows, Linux and macOS, including installations using logical replication, backup or change-data-capture accounts.

The replication protocol accepted an unrestricted logical-decoding plugin path, allowing a non-superuser REPLICATION role to load a chosen library as the PostgreSQL operating-system account.

Detail and 2 sources

The attacker still needs a library-delivery route: Cyera demonstrated an SMB-hosted DLL on Windows, while NFS automounts or a separate file-write primitive can supply the path elsewhere.

Once loaded, the library can modify pg_authid and install persistent superuser access.

Fixed releases are available, but anti-rollback is not enforced and pre-fix images remain accepted.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Friday, September 4, 2026