Threat Advisory

PostgreSQL Flaw Lets Attackers Execute Arbitrary Code with Replication Access

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A newly disclosed PostgreSQL vulnerability affecting Unknown versions, PostgreSQL did not properly restrict the library path provided as an output plugin name, tracked as and nicknamed PostGREShell, is a critical flaw that could allow attackers with low-level replication access to execute arbitrary code on database servers. This issue affects non-superuser PostgreSQL accounts that have the REPLICATION attribute, typically used for backups, replication, disaster recovery, and change data capture operations.

The vulnerability stems from inadequate library-path restrictions in the logical replication workflow, which has existed for roughly 12 years. An attacker with REPLICATION privileges can abuse the logical decoding feature to force PostgreSQL to load an attacker-controlled library, executing malicious code with the permissions of the PostgreSQL server process.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A newly disclosed PostgreSQL vulnerability affecting Unknown versions, PostgreSQL did not properly restrict the library path provided as an output plugin name, tracked as and nicknamed PostGREShell, is a critical flaw that could allow attackers with low-level replication access to execute arbitrary code on database servers. This issue affects non-superuser PostgreSQL accounts that have the REPLICATION attribute, typically used for backups, replication, disaster recovery, and change data capture operations.

The vulnerability stems from inadequate library-path restrictions in the logical replication workflow, which has existed for roughly 12 years. An attacker with REPLICATION privileges can abuse the logical decoding feature to force PostgreSQL to load an attacker-controlled library, executing malicious code with the permissions of the PostgreSQL server process.[emaillocker id="1283"]

Exploitation requires a PostgreSQL account with REPLICATION, wal_level = logical, and reachable SMB port 445. This vulnerability is concerning because it affects operational database accounts that may appear low-risk but can provide a path to code execution and full compromise of a PostgreSQL environment.

RECOMMENDATION:

We recommend you to update PostgreSQL to version 18.6, 17.11, 16.15, 15.19, or 14.24.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu