PostgreSQL fails to check type USAGE privilege (CVE-2026-6470)
A missing authorization check in PostgreSQL allows an object creator to cause denial of service on ALTER and DROP operations of a type by creating dependencies on that type. This occurs because certain DDL commands, such as assigning a range subtype and referencing the type from an SQL expression, do not properly verify USAGE privileges. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected. A patch is available to address this issue.
AI Analysis
Technical Summary
CVE-2026-6470 is a vulnerability in PostgreSQL where the system fails to check the USAGE privilege on types during some DDL operations. While many DDL commands correctly enforce privilege checks, assigning a range subtype and referencing the type from an SQL expression do not. This flaw allows an object creator to create dependencies on a type that can lead to denial of service against ALTER and DROP operations on that type. The vulnerability affects PostgreSQL versions prior to 14.24, 15.19, 16.15, 17.11, and 18.6. A patch has been made available to fix this issue.
Potential Impact
An attacker with the ability to create objects in PostgreSQL can exploit this vulnerability to cause denial of service by preventing ALTER and DROP operations on certain types. This could interfere with database schema modifications and maintenance, potentially impacting database availability or administrative operations.
Mitigation Recommendations
A patch is available for this vulnerability. Users should upgrade to PostgreSQL versions 14.24, 15.19, 16.15, 17.11, or 18.6 or later, where the issue is fixed. Applying the official updates will remediate the missing privilege check and prevent the denial of service condition.
PostgreSQL fails to check type USAGE privilege (CVE-2026-6470)
Description
A missing authorization check in PostgreSQL allows an object creator to cause denial of service on ALTER and DROP operations of a type by creating dependencies on that type. This occurs because certain DDL commands, such as assigning a range subtype and referencing the type from an SQL expression, do not properly verify USAGE privileges. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected. A patch is available to address this issue.
Affected software
pkg:deb/postgresql/postgresqlRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-6470 is a vulnerability in PostgreSQL where the system fails to check the USAGE privilege on types during some DDL operations. While many DDL commands correctly enforce privilege checks, assigning a range subtype and referencing the type from an SQL expression do not. This flaw allows an object creator to create dependencies on a type that can lead to denial of service against ALTER and DROP operations on that type. The vulnerability affects PostgreSQL versions prior to 14.24, 15.19, 16.15, 17.11, and 18.6. A patch has been made available to fix this issue.
Potential Impact
An attacker with the ability to create objects in PostgreSQL can exploit this vulnerability to cause denial of service by preventing ALTER and DROP operations on certain types. This could interfere with database schema modifications and maintenance, potentially impacting database availability or administrative operations.
Mitigation Recommendations
A patch is available for this vulnerability. Users should upgrade to PostgreSQL versions 14.24, 15.19, 16.15, 17.11, or 18.6 or later, where the issue is fixed. Applying the official updates will remediate the missing privilege check and prevent the denial of service condition.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-2pm8-9426-243p
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-6470"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a7e0366bf8831d5398f854b
Added to database: 08/13/2026, 17:48:22 UTC
Last enriched: 09/08/2026, 15:13:56 UTC
Last updated: 09/26/2026, 01:47:43 UTC
Views: 80
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.