THREAT OPS › Threat News › [NVD] CVE-2026-14666 (MEDIUM 4.2) — Incomplete tracking in PostgreSQL of changes to role membership, role attributes, and database ownership allows a query to continue using cached row-level security policies after those changes require a different policy, via plan reuse. Stale policies continue until some other e
[NVD] CVE-2026-14666 (MEDIUM 4.2) — Incomplete tracking in PostgreSQL of changes to role membership, role attributes, and database ownership allows a query to continue using cached row-level security policies after those changes require a different policy, via plan reuse. Stale policies continue until some other e
CVE-2026-14666 CVSS: 4.2 MEDIUM Published: 2026-08-13T13:17:43.993
Incomplete tracking in PostgreSQL of changes to role membership, role attributes, and database ownership allows a query to continue using cached row-level security policies after those changes require a different policy, via plan reuse. Stale policies continue until some other event invalidates the cache or connection termination
Indicators of compromise
- CVE-2026-14666cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-14666