PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to execute arbitrary code by abusing operators, domain casts, or view subqueries that carry untrusted expressions. When these objects are evaluated in the context of the extension’s masking mechanisms, the malicious code can run with elevated privileges. The issue is fixed in PostgreSQL Anonymizer 3.1.4 and later versions
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://gitlab.com/dalibo/postgresql_anonymizer/-/issues/665 |
|
History
Sun, 06 Sep 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dalibo
Dalibo postgresql Anonymizer |
|
| Vendors & Products |
Dalibo
Dalibo postgresql Anonymizer |
Sun, 06 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to execute arbitrary code by abusing operators, domain casts, or view subqueries that carry untrusted expressions. When these objects are evaluated in the context of the extension’s masking mechanisms, the malicious code can run with elevated privileges. The issue is fixed in PostgreSQL Anonymizer 3.1.4 and later versions | |
| Title | PostgreSQL Anonymizer: unprivileged masked users can execute code via operators, domain casts and view subqueries | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: PostgreSQL
Published:
Updated: 2026-09-06T15:25:32.533Z
Reserved: 2026-08-12T16:09:08.888Z
Link: CVE-2026-19633
No data.
Status : Received
Published: 2026-09-06T16:16:49.583
Modified: 2026-09-06T16:16:49.583
Link: CVE-2026-19633
No data.
OpenCVE Enrichment
Updated: 2026-09-06T16:30:07Z
Weaknesses