---
title: "CVE-2026-2004\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2026-2004?format=md
keywords: index, follow
---

# CVE-2026-2004

Publication date 12 February 2026

Last updated 4 March 2026

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**8.8 · High**

[Score breakdown](https://ubuntu.com/security/CVE-2026-2004?format=md#impact-score)

Toggle side navigation

## Description

Missing validation of type of input in PostgreSQL intarray extension
selectivity estimator function allows an object creator to execute
arbitrary code as the operating system user running the database. Versions
before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2026-2004?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| postgresql-10 | 26.04 LTS resolute | Not in release |
| 25.10 questing | Not in release |
| 24.04 LTS noble | Not in release |
| 22.04 LTS jammy | Not in release |
| 18.04 LTS bionic | Needs evaluation |
| postgresql-12 | 26.04 LTS resolute | Not in release |
| 25.10 questing | Not in release |
| 24.04 LTS noble | Not in release |
| 22.04 LTS jammy | Not in release |
| 20.04 LTS focal | Needs evaluation |
| postgresql-14 | 26.04 LTS resolute | Not in release |
| 25.10 questing | Not in release |
| 24.04 LTS noble | Not in release |
| 22.04 LTS jammy | Fixed 14.22-0ubuntu0.22.04.1 |
| postgresql-16 | 26.04 LTS resolute | Not in release |
| 25.10 questing | Not in release |
| 24.04 LTS noble | Fixed 16.13-0ubuntu0.24.04.1 |
| 22.04 LTS jammy | Not in release |
| postgresql-17 | 26.04 LTS resolute | Not in release |
| 25.10 questing | Fixed 17.9-0ubuntu0.25.10.1 |
| 24.04 LTS noble | Not in release |
| 22.04 LTS jammy | Not in release |
| postgresql-18 | 26.04 LTS resolute | Not affected |
| 25.10 questing | Not in release |
| 24.04 LTS noble | Not in release |
| 22.04 LTS jammy | Not in release |
| postgresql-9.3 | 26.04 LTS resolute | Not in release |
| 25.10 questing | Not in release |
| 24.04 LTS noble | Not in release |
| 22.04 LTS jammy | Not in release |
| 14.04 LTS trusty | Vulnerable, fix deferred |
| postgresql-9.5 | 26.04 LTS resolute | Not in release |
| 25.10 questing | Not in release |
| 24.04 LTS noble | Not in release |
| 22.04 LTS jammy | Not in release |
| 16.04 LTS xenial | Needs evaluation |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [leosilva](https://launchpad.net/~leosilva)

PostgreSQL 9.3 is end of life upstream, and no updates are
are available. Marking as deferred in -esm-main releases.

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

8.8 · High

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | Low |
  | Privileges required | Low |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | High |
  | Integrity impact | High |
  | Availability impact | High |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 8.8 · High |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-2004)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2026-2004)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2026-2004)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2026-2004)

### Related Ubuntu Security Notices (USN)

+ [USN-8072-1](https://usn.ubuntu.com/USN-8072-1)
+ PostgreSQL vulnerabilities
+ 4 March 2026

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2026-2004>
* <https://www.postgresql.org/about/news/postgresql-182-178-1612-1516-and-1421-released-3235/>
* <https://www.postgresql.org/support/security/CVE-2026-2004/>
