LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →

CVE-2026-2004 - Vulnerability Analysis

HighCVSS: 8.8

Last Updated: February 12, 2026

PostgreSQL intarray - Command Injection

Published: February 12, 2026Updated: February 12, 2026Remote Exploitable

Overview

PostgreSQL intarray extension < 18.2, 17.8, 16.12, 15.16, and 14.21 contains a command injection caused by missing input type validation in selectivity estimator function, letting object creators execute arbitrary OS commands, exploit requires object creation privileges.

Severity & Score

Severity: High
CVSS Score: 8.8
EPSS Score: 9.5%(Probability of exploitation in next 30 days)

Impact

Object creators can execute arbitrary OS commands as the database user, potentially leading to full system compromise.

Mitigation

Upgrade to PostgreSQL 18.2, 17.8, 16.12, 15.16, 14.21 or later.

Social Media Activity(2 posts)

TheHackerWire
TheHackerWire
@thehackerwire
Feb 12, 2026

🟠 CVE-2026-2004 - High (8.8) Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object creator to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-2004/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post
Raphael
Raphael
@0x3e4
Feb 12, 2026

few new #postgresql vulns out there today šŸ” CVE-2026-2004 CVE-2026-2004 Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object creator to execute arbitrary code as the operating system user running the database. šŸ“Š CVSS Score: 8.8 āš ļø Severity: High šŸ“… Published: 02/12/2026, 02:16 PM šŸ·ļø Aliases: CVE-2026-2004 šŸ›”ļø CWE: CWE-1287 šŸ“š References: https://www.postgresql.org/support/security/CVE-2026-2004/ šŸ”— https://hecate.pw/vulnerability/CVE-2026-2004 #cve #vulnerability #hecate

View original post

Details

CVE ID
CVE-2026-2004
Severity
High
CVSS Score
8.8
Type
command_injection
Status
unconfirmed
EPSS
9.5%
Social Posts
2

CWE

  • CWE-1287

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Score

9.5%Probability of exploitation in the next 30 days