CVE-2026-16238: PostgreSQL type confusion in pg_restore_attribute_stats() executes arbitrary code
Type confusion in PostgreSQL pgrestoreattributestats() allows an object creator to execute arbitrary code as the operating system user running the database, via conflation of range and multirange values. Within major version 18, minor versions before PostgreSQL 18.5 are affected. Versions before PostgreSQL 18 are unaffected.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
PostgreSQLto a version that resolves this vulnerability.Fixed in 18.5
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16238?
CVE-2026-16238 has a severity score of 8.8, which is considered high.
How do I fix CVE-2026-16238?
To mitigate CVE-2026-16238, upgrade PostgreSQL to version 18.5 or later.
What types of systems are affected by CVE-2026-16238?
CVE-2026-16238 affects PostgreSQL version 18 and earlier minor versions before 18.5.
What is the impact of CVE-2026-16238?
CVE-2026-16238 allows an attacker to execute arbitrary code as the operating system user running the PostgreSQL database.
Is there a workaround for CVE-2026-16238?
There are no official workarounds for CVE-2026-16238, so upgrading to the patched version is strongly recommended.