THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-19633 (HIGH 8.8) — PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to execute arbitrary code by abusing operators, domain casts, or view subqueries that carry untrusted expressions. When these objects are evaluated in the context of the extension’s masking mecha

[NVD] CVE-2026-19633 (HIGH 8.8) — PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to execute arbitrary code by abusing operators, domain casts, or view subqueries that carry untrusted expressions. When these objects are evaluated in the context of the extension’s masking mecha

mednvdPublished 2026-09-06

CVE-2026-19633 CVSS: 8.8 HIGH Published: 2026-09-06T16:16:49.583

PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to execute arbitrary code by abusing operators, domain casts, or view subqueries that carry untrusted expressions. When these objects are evaluated in the context of the extension’s masking mechanisms, the malicious code can run with elevated privil

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-19633