Medium severity6.4NVD Advisory· Published Jun 11, 2026· Updated Jun 16, 2026
CVE-2026-11945
CVE-2026-11945
Description
PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a JSON document and placing malicious code inside a particular key-value pair. If a superuser calls the import_database_rules() or import_roles_rules() functions, the malicious code is executed with superuser privileges. The problem is resolved in PostgreSQL Anonymizer 3.1.1 and further versions
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2(expand)+ 1 more
- (no CPE)
- (no CPE)range: <3.1.1
Patches
Vulnerability mechanics
References
1- gitlab.com/dalibo/postgresql_anonymizer/-/issues/643nvdExploitIssue TrackingPatchVendor Advisory
News mentions
0No linked articles in our index yet.