CVE-2026-6464: Inclusion of Functionality from Untrusted Control Sphere in PostgreSQL
Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as psql commands, via error injection. If the "COPY FROM STDIN" or "\copy FROM STDIN" command fails before the server indicates that it awaits input rows, psql processes the in-line data rows as psql commands. "COPY FROM" with a filename is unaffected. The server administrator has no inherent control over the data rows, so a complete attack requires the attacker to separately acquire control of both the server and the data rows. Alternatively, an attacker controlling data rows alone might complete an attack through a coincidental error that they don't control. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
AI Analysis
Technical Summary
The vulnerability involves untrusted data inclusion in the PostgreSQL psql client's COPY command. Specifically, if "COPY FROM STDIN" or "\copy FROM STDIN" fails early, psql processes subsequent data lines as commands rather than data. This can allow a server administrator to execute unintended psql commands via error injection. The attack requires either control over both the server and the data rows or a coincidental error that the attacker does not control. The issue does not affect "COPY FROM" when used with a filename. Affected versions are all prior to PostgreSQL 14.24, 15.19, 16.15, 17.11, and 18.5.
Potential Impact
Successful exploitation could allow execution of arbitrary psql commands by a server administrator, leading to high confidentiality, integrity, and availability impacts. However, exploitation requires either control of both the server and the data rows or a coincidental error, limiting the attack surface. The vulnerability does not allow remote code execution by an unprivileged user alone.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is released, avoid using "COPY FROM STDIN" or "\copy FROM STDIN" with untrusted data in affected versions. Monitor PostgreSQL vendor communications for patches addressing this issue.
CVE-2026-6464: Inclusion of Functionality from Untrusted Control Sphere in PostgreSQL
Description
Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as psql commands, via error injection. If the "COPY FROM STDIN" or "\copy FROM STDIN" command fails before the server indicates that it awaits input rows, psql processes the in-line data rows as psql commands. "COPY FROM" with a filename is unaffected. The server administrator has no inherent control over the data rows, so a complete attack requires the attacker to separately acquire control of both the server and the data rows. Alternatively, an attacker controlling data rows alone might complete an attack through a coincidental error that they don't control. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
CVSS v3.1
Score 8.1high
Affected software
PostgreSQL
pkg:deb/postgresql/postgresqlRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability involves untrusted data inclusion in the PostgreSQL psql client's COPY command. Specifically, if "COPY FROM STDIN" or "\copy FROM STDIN" fails early, psql processes subsequent data lines as commands rather than data. This can allow a server administrator to execute unintended psql commands via error injection. The attack requires either control over both the server and the data rows or a coincidental error that the attacker does not control. The issue does not affect "COPY FROM" when used with a filename. Affected versions are all prior to PostgreSQL 14.24, 15.19, 16.15, 17.11, and 18.5.
Potential Impact
Successful exploitation could allow execution of arbitrary psql commands by a server administrator, leading to high confidentiality, integrity, and availability impacts. However, exploitation requires either control of both the server and the data rows or a coincidental error, limiting the attack surface. The vulnerability does not allow remote code execution by an unprivileged user alone.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is released, avoid using "COPY FROM STDIN" or "\copy FROM STDIN" with untrusted data in affected versions. Monitor PostgreSQL vendor communications for patches addressing this issue.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- PostgreSQL
- Date Reserved
- 2026-04-17T00:19:12.645Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a7dc619bf8831d5393e5413
Added to database: 08/13/2026, 13:26:49 UTC
Last enriched: 08/13/2026, 16:12:29 UTC
Last updated: 09/27/2026, 01:47:44 UTC
Views: 74
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.