THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-6470 (MEDIUM 4.3) — Missing authorization in PostgreSQL DDL commands allows an object creator to achieve denial of service against ALTER and DROP of the type, via creating a dependency on the type. Many DDL operations did check the privilege, but assigning a range subtype and referencing the type f

[NVD] CVE-2026-6470 (MEDIUM 4.3) — Missing authorization in PostgreSQL DDL commands allows an object creator to achieve denial of service against ALTER and DROP of the type, via creating a dependency on the type. Many DDL operations did check the privilege, but assigning a range subtype and referencing the type f

mednvdPublished 2026-08-13

CVE-2026-6470 CVSS: 4.3 MEDIUM Published: 2026-08-13T13:19:16.600

Missing authorization in PostgreSQL DDL commands allows an object creator to achieve denial of service against ALTER and DROP of the type, via creating a dependency on the type. Many DDL operations did check the privilege, but assigning a range subtype and referencing the type from an SQL expression did not. Versions before Postg

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-6470