CVE-2026-96883: Type confusion in AWS pgcollection allows remote code execution
pgcollection is an open source extension to PostgreSQL. A type confusion issue in AWS pgcollection 2.0.0 through 2.1.1 might allow an authenticated remote user to execute arbitrary code as the postgres operating system user via crafted SQL statements that rely on mismatched type metadata in collection value retrieval and array conversion functions.
To remediate this issue, users should upgrade to version 2.1.2 or later.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
AWS pgcollectionto a version that resolves this vulnerability.Fixed in 2.1.2
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated remote user who can submit crafted SQL statements to a PostgreSQL instance with a vulnerable pgcollection version installed may exploit it. Successful exploitation can execute code as the postgres operating system user.
Are all pgcollection versions affected?
The affected versions are AWS pgcollection 2.0.0 through 2.1.1. Version 2.1.2 or later remediates the issue.
What is the recommended remediation?
Upgrade AWS pgcollection to version 2.1.2 or later.