THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-15741 (HIGH 8.8) — SQL injection in PostgreSQL EXTRACT() deparse allows an object owner to execute arbitrary SQL as a superuser via a hostile object definition. Attacks affect expression deparse consumers broadly, including pg_dump, psql commands like \sf, and any similar usage in non-core tools.

[NVD] CVE-2026-15741 (HIGH 8.8) — SQL injection in PostgreSQL EXTRACT() deparse allows an object owner to execute arbitrary SQL as a superuser via a hostile object definition. Attacks affect expression deparse consumers broadly, including pg_dump, psql commands like \sf, and any similar usage in non-core tools.

mednvdPublished 2026-08-13

CVE-2026-15741 CVSS: 8.8 HIGH Published: 2026-08-13T13:17:45.957

SQL injection in PostgreSQL EXTRACT() deparse allows an object owner to execute arbitrary SQL as a superuser via a hostile object definition. Attacks affect expression deparse consumers broadly, including pg_dump, psql commands like \sf, and any similar usage in non-core tools. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19,

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-15741