---
title: "CVE-2026-6471\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2026-6471?format=md
keywords: index, follow
---

# CVE-2026-6471

Publication date 13 August 2026

Last updated 2 September 2026

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**7.2 · High**

[Score breakdown](https://ubuntu.com/security/CVE-2026-6471?format=md#impact-score)

Toggle side navigation

## Description

Missing authorization in PostgreSQL logical decoding allows a non-superuser
holding REPLICATION privilege to dlopen any file visible to the operating
system account running the server, via the choice of logical decoding
plugin. This in turn runs arbitrary code as that account. Versions before
PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2026-6471?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| postgresql-18 | 26.04 LTS resolute | Fixed 18.6-0ubuntu0.26.04.1 |
| 24.04 LTS noble | Not in release |
| 22.04 LTS jammy | Not in release |
| postgresql-16 | 26.04 LTS resolute | Not in release |
| 24.04 LTS noble | Fixed 16.15-0ubuntu0.24.04.1 |
| 22.04 LTS jammy | Not in release |
| postgresql-14 | 26.04 LTS resolute | Not in release |
| 24.04 LTS noble | Not in release |
| 22.04 LTS jammy | Fixed 14.24-0ubuntu0.22.04.1 |
| postgresql-12 | 26.04 LTS resolute | Not in release |
| 24.04 LTS noble | Not in release |
| 22.04 LTS jammy | Not in release |
| 20.04 LTS focal | Needs evaluation |
| postgresql-10 | 26.04 LTS resolute | Not in release |
| 24.04 LTS noble | Not in release |
| 22.04 LTS jammy | Not in release |
| 18.04 LTS bionic | Needs evaluation |
| postgresql-9.5 | 26.04 LTS resolute | Not in release |
| 24.04 LTS noble | Not in release |
| 22.04 LTS jammy | Not in release |
| 16.04 LTS xenial | Needs evaluation |
| postgresql-9.3 | 26.04 LTS resolute | Not in release |
| 24.04 LTS noble | Not in release |
| 22.04 LTS jammy | Not in release |
| 14.04 LTS trusty | Vulnerable, fix deferred |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [leosilva](https://launchpad.net/~leosilva)

PostgreSQL 9.3 is end of life upstream, and no updates are
are available. Marking as deferred in -esm-main releases.
PostgreSQL 9.3 is end of life upstream, and no updates are
are available. Marking as deferred in -esm-main releases.
PostgreSQL 9.3 is end of life upstream, and no updates are
are available. Marking as deferred in -esm-main releases.
PostgreSQL 9.3 is end of life upstream, and no updates are
are available. Marking as deferred in -esm-main releases.

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

7.2 · High

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | Low |
  | Privileges required | High |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | High |
  | Integrity impact | High |
  | Availability impact | High |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 7.2 · High |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6471)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2026-6471)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2026-6471)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2026-6471)

### Related Ubuntu Security Notices (USN)

+ [USN-8653-1](https://usn.ubuntu.com/USN-8653-1)
+ PostgreSQL vulnerabilities
+ 20 August 2026

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2026-6471>
* <https://www.postgresql.org/support/security/CVE-2026-6471/>
* <https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/>
