« Volver al listado

CVE-2026-6475

Estado: AnalizadaAlta (8.8)—

Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Requiere interacción del usuario (UI:R, abrir/usar pg_basebackup). El atacante sobrescribe archivos (.bashrc) para secuestrar la sesión del SO; posterior confianza implícita en shared_preload_libraries (T1574.006).

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-6475",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-6475",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-05-14T00:00:00+00:00"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "PostgreSQL",
          "versions": [
            {
              "status": "affected",
              "version": "18",
              "lessThan": "18.4",
              "versionType": "rpm"
            },
            {
              "status": "affected",
              "version": "17",
              "lessThan": "17.10",
              "versionType": "rpm"
            },
            {
              "status": "affected",
              "version": "16",
              "lessThan": "16.14",
              "versionType": "rpm"
            },
            {
              "status": "affected",
              "version": "15",
              "lessThan": "15.18",
              "versionType": "rpm"
            },
            {
              "status": "affected",
              "version": "0",
              "lessThan": "14.23",
              "versionType": "rpm"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-05-14T14:16:25.113",
  "references": [
    {
      "url": "https://www.postgresql.org/support/security/CVE-2026-6475/",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
      "description": [
        {
          "lang": "en",
          "value": "CWE-61"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account.  It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries.  Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM.  Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected."
    }
  ],
  "lastModified": "2026-06-17T11:00:51.430",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C432AE18-DD50-40EB-B46A-9283F30081DA",
              "versionEndExcluding": "14.23"
            },
            {
              "criteria": "cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9D8D994F-ABAB-4AC2-992F-320F4868698D",
              "versionEndExcluding": "15.18",
              "versionStartIncluding": "15.0"
            },
            {
              "criteria": "cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B58AE3D3-E1C9-45D2-AA92-A3D135B77A8A",
              "versionEndExcluding": "16.14",
              "versionStartIncluding": "16.0"
            },
            {
              "criteria": "cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A19538E9-DBB9-4396-AC04-17943E82C411",
              "versionEndExcluding": "17.10",
              "versionStartIncluding": "17.0"
            },
            {
              "criteria": "cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F8DB17ED-67AD-41F2-B272-27AF5B4FA2B0",
              "versionEndExcluding": "18.4",
              "versionStartIncluding": "18.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"
}