Update PostgreSQL to the patched versions: 18.6, 17.11, 16.15, 15.19, or 14.24 or later. Apply the released security updates immediately. Review and restrict REPLICATION attribute assignments to trusted accounts only. Disable logical decoding if not required for your deployment.
Quick answers
What is CVE-2026-6471?
Update PostgreSQL to the patched versions: 18.6, 17.11, 16.15, 15.19, or 14.24 or later. Apply the released security updates immediately. Review and restrict REPLICATION attribute assignments to trusted accounts only. Disable logical decoding if not required for your deployment.
How severe is CVE-2026-6471?
high, CVSS 7.2
Is CVE-2026-6471 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-6471 be mitigated?
Update PostgreSQL to the patched versions: 18.6, 17.11, 16.15, 15.19, or 14.24 or later. Apply the released security updates immediately. Review and restrict REPLICATION attribute assignments to trusted accounts only. Disable logical decoding if not required for your deployment.
CVSS
7.2
Vendor
PostgreSQL
Published
Sep 30, 2026 · 08:05
Patch
Unknown / not confirmed
Affected products
PostgreSQL
Mitigation
Update PostgreSQL to the patched versions: 18.6, 17.11, 16.15, 15.19, or 14.24 or later. Apply the released security updates immediately. Review and restrict REPLICATION attribute assignments to trusted accounts only. Disable logical decoding if not required for your deployment.
PostgreSQL has released security updates to address a vulnerability present since the introduction of logical decoding in PostgreSQL 9.4 (2014). Tracked as CVE-2026-6471, the flaw carries a CVSS score of 7.2 and allows an account with the REPLICATION attribute to execute arbitrary code as the operating-system user running the database server. Versions prior to 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.