TL;DR
PostgreSQL developers patched a critical integer wraparound flaw in the fuzzystrmatch module. This PostgreSQL RCE vulnerability permits low-privileged database users to execute arbitrary commands as the host operating system user. The details of the vulnerability and the proof-of-concept exploit code have been publicly disclosed, requiring immediate administrative attention.
- CVE: CVE-2026-15742
- CVSS: 8.8 (High · CVSSv3)
- Product: n/a PostgreSQL
- Affected: 18, 17, 16, 15, < 14.24
- Impact: PostgreSQL fuzzystrmatch writes effectively-arbitrary addresses, via integer wraparound
- Status: No confirmed exploitation yet
- Patched in: 18.6, 17.11, 16.15, 15.19 (+1 more)
- EPSS: 0.6% (30-day)
- Action: Update to 18.6, 17.11, 16.15, 15.19 (+1 more) now
Running Infra, AppSec, and SOC teams? Tag CVE alerts by team automatically.
Try Team free for 14 daysWhy It Matters
Industry telemetry estimates that millions of active production databases deploy PostgreSQL globally. Therefore, security defects in bundled extensions create substantial exposure for enterprise environments. The vulnerability, tracked as CVE-2026-15742, carries a high CVSS base score of 8.8. An authenticated user can achieve full server compromise by querying specific extension functions.
Security researchers confirmed no active exploitation in the wild at this time. However, the details of the vulnerability and the proof-of-concept exploit code have been publicly disclosed by a researcher on GitHub. This public disclosure drastically lowers the barrier for attackers to weaponize the defect against unpatched deployments. Consequently, updating exposed database clusters is an absolute priority.
How The Attack Works
The flaw exists within the input processing logic of the optional fuzzystrmatch contrib module. A malicious user triggers the defect by supplying extreme inputs to the levenshtein() or levenshtein_less_equal() SQL functions. When the module calculates string distances, the extreme parameters cause an integer wraparound condition.
This mathematical overflow bypasses internal boundary checks. Consequently, the attacker can direct memory writes to a huge range of addresses inside the database process. By corrupting heap memory and overwriting function pointers, the attacker hijacks the execution flow. This memory corruption translates directly into unauthorized operating system command execution under the privileges of the PostgreSQL service account.
Affected Versions
This PostgreSQL RCE vulnerability affects multiple active release branches. Vulnerable deployments include PostgreSQL 18 prior to 18.6, 17 before 17.11, and 16 before 16.15. The flaw also impacts version 15 prior to 15.19 and version 14 before 14.24. Systems are only vulnerable if they actively install and utilize the fuzzystrmatch extension.
Patch Or Mitigation Steps
Database administrators must install the official security patches immediately. The PostgreSQL project resolved the issue in versions 18.6, 17.11, 16.15, 15.19, and 14.24.
Furthermore, security teams can analyze the proof-of-concept exploit code to build custom detection rules. If you cannot apply the patch immediately, uninstall the fuzzystrmatch module to neutralize the threat vector entirely. Securing your database environment prevents unauthorized users from escalating their privileges to the underlying operating system.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!