CVE-2026-11945

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
11/06/2026
Last modified:
16/06/2026

Description

PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a JSON document and placing malicious code inside a particular key-value pair. If a superuser calls the import_database_rules() or import_roles_rules() functions, the malicious code is executed with superuser privileges. The problem is resolved in PostgreSQL Anonymizer 3.1.1 and further versions

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:dalibo:postgresql_anonymizer:*:*:*:*:*:postgresql:*:* 3.1.1 (excluding)


References to Advisories, Solutions, and Tools