THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-14680 (HIGH 8.8) — Type confusion with PostgreSQL "internal" data type arguments allows any user to execute arbitrary code as the operating system user running the database, via calls to functions with that argument type. Type "internal" represents a class of mutually-incompatible data structures

[NVD] CVE-2026-14680 (HIGH 8.8) — Type confusion with PostgreSQL "internal" data type arguments allows any user to execute arbitrary code as the operating system user running the database, via calls to functions with that argument type. Type "internal" represents a class of mutually-incompatible data structures

mednvdPublished 2026-08-13

CVE-2026-14680 CVSS: 8.8 HIGH Published: 2026-08-13T13:17:45.400

Type confusion with PostgreSQL "internal" data type arguments allows any user to execute arbitrary code as the operating system user running the database, via calls to functions with that argument type. Type "internal" represents a class of mutually-incompatible data structures not intended for access from SQL. The system intended

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-14680