THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-14666 (MEDIUM 4.2) — Incomplete tracking in PostgreSQL of changes to role membership, role attributes, and database ownership allows a query to continue using cached row-level security policies after those changes require a different policy, via plan reuse. Stale policies continue until some other e

[NVD] CVE-2026-14666 (MEDIUM 4.2) — Incomplete tracking in PostgreSQL of changes to role membership, role attributes, and database ownership allows a query to continue using cached row-level security policies after those changes require a different policy, via plan reuse. Stale policies continue until some other e

mednvdPublished 2026-08-13

CVE-2026-14666 CVSS: 4.2 MEDIUM Published: 2026-08-13T13:17:43.993

Incomplete tracking in PostgreSQL of changes to role membership, role attributes, and database ownership allows a query to continue using cached row-level security policies after those changes require a different policy, via plan reuse. Stale policies continue until some other event invalidates the cache or connection termination

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-14666