Uncontrolled Search Path (DLL Hijack)Weakness · CWE-427

CVE-2026-2360

HIGH · 8.0 CVSS v3.1 Published 2026-02-11
Mitigation only
No fix yet — a mitigation exists. There is no fixed release. A documented workaround reduces exposure in the meantime.
See remediation →
86/100
Remediation priority · High
Remotely reachable Zero-click

Official description Straight from the sourceThe vendor's or NVD's own wording, published unedited. Authoritative, but often terse — it says what broke, rarely what to do.

NVD · unedited
PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a custom operator in the public schema and place malicious code in that operator. This operator will later be executed with superuser privileges when the extension is created. The risk is higher with PostgreSQL 14 or with instances upgraded from PostgreSQL 14 or a prior version. With PostgreSQL 15 and later, the creation permission on the public schema is revoked by default and this exploit can only be achieved if a superuser adds a new schema in her/his own search_path and grants the CREATE privilege on that schema to untrusted users, both actions being clearly discouraged by the PostgreSQL documentation. The problem is resolved in PostgreSQL Anonymizer 3.0.1 and further versions

Technical summary Written by usOur analysis, written from the advisory, the CVSS vector and the affected-version data. It adds context the advisory leaves out, and never invents facts that are not in the source.

dbcve analysis · high confidence

PostgreSQL Anonymizer before 3.0.1 allows untrusted users to escalate to superuser privileges by creating a malicious custom operator in the public schema. When the extension is created, it executes this operator with superuser privileges. PostgreSQL 14 or upgraded instances are at higher risk, while PostgreSQL 15+ has safer defaults.

MitigationUpgrade PostgreSQL Anonymizer to version 3.0.1 or later. For PostgreSQL 14 or upgraded instances, additionally audit the database for suspicious operators in the public schema and review search_path configurations.

Verify against the referenced sources before acting — the references below are authoritative for this CVE, this summary is not.

CVSS breakdown How the score is builtThe industry scoring standard. It rates how the flaw is reached, what it takes to exploit, and what an attacker gains — the score is derived from those, not the other way round.

From the vector
Attack vector
Network
Complexity
High
Privileges
High
User interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

Am I affected? How to checkSteps we derive from the advisory and the affected-version data, so you can decide whether this CVE reaches your setup. They are a guide, not a scan — your own configuration is the authority.

dbcve checks

Work through these to decide whether this CVE applies to you.

  1. Verify PostgreSQL Anonymizer extension is installed
    Query pg_extension catalog: SELECT extname, extversion FROM pg_extension WHERE extname = 'anon';
    Affected if No rows returned means the extension is not installed and the vulnerability does not apply.
  2. Determine installed PostgreSQL Anonymizer version
    If the extension exists, run: SELECT anon.version(); or check pg_extension.extversion for the 'anon' extension.
    Affected if Version is below 3.0.1 - the vulnerability is present in this installation.
  3. Check PostgreSQL server version
    Run: SELECT version(); or SHOW server_version;
    Affected if Running PostgreSQL 14 or any upgraded instance increases the risk profile significantly.
  4. Inspect custom operators in the public schema
    Query pg_operator for operators in public schema created by non-superusers: SELECT proname, pronamespace::regnamespace FROM pg_proc JOIN pg_namespace ON pronamespace = oid WHERE pronamespace = 'public'::regnamespace AND proowner != (SELECT oid FROM pg_roles WHERE rolname = 'postgres');
    Affected if Any custom operators exist in public schema created by untrusted users - these could be malicious.
  5. Review current search_path setting
    Run: SHOW search_path;
    Affected if Search_path includes 'public' without explicit schema qualification allows operators in public schema to be resolved automatically.

You are affected if PostgreSQL Anonymizer version is below 3.0.1 AND untrusted users can create or have created custom operators in the public schema, especially on PostgreSQL 14 or upgraded instances.

Generated from the published advisory. Verify against your own configuration.

Check your environment

Paste your version and any relevant configuration and it will be compared against the affected criteria above. Do not include secrets or credentials.

AI-assisted, checked against the advisory. Informational, not a guarantee.

Remediation Closing itWhat it takes to close this. Where a vendor fix exists we point at it; where none exists we say so plainly, and can build one. Effort estimates are scoped from the advisory, not from your codebase.

dbcve · scoped
Mitigation available No clean upgrade yet — mitigate in the meantime
Mitigation

Upgrade PostgreSQL Anonymizer to version 3.0.1 or later. For PostgreSQL 14 or upgraded instances, additionally audit the database for suspicious operators in the public schema and review search_path configurations.

Recommended fix High confidence

PostgreSQL Anonymizer 3.0.1 or later

  1. 1. Identify the current installed version of the PostgreSQL Anonymizer extension using psql: SELECT * FROM pg_extension WHERE extname = 'anon';
  2. 2. If the installed version is earlier than 3.0.1, upgrade the PostgreSQL Anonymizer extension to version 3.0.1 or later
  3. 3. If using PostgreSQL 14 or an instance upgraded from PostgreSQL 14 or prior, ensure you are also on PostgreSQL Anonymizer 3.0.1+ which contains the fix
  4. 4. After upgrading, verify the new version is active: SELECT anon.extension_version();
  5. 5. As a security best practice, ensure the public schema does not have CREATE permission granted to untrusted users (this is default in PostgreSQL 15+)
Caveat Review extension documentation for any changes in behavior or configuration requirements between your current version and 3.0.1

Generated from the published advisory — verify against the referenced sources before acting.

Have this fixed Scoped from the published advisory
  • Consultation3.0 h
  • Implementation2.0 h
  • Testing3.0 h
  • Review / QA2.0 h
10.0 hours of engineering $1,770
Get help mitigating

An estimate, not a bill — we confirm scope with you before any work starts. Need it this week? Rush from $2,832.

Scan for this in your stack

Free · runs locally
dbcve dependency scanner

Check whether your project pulls in CVE-2026-2360 — or any other known-vulnerable package — straight from your lock files. Free and open source; it runs locally and uploads nothing.

References Go to the primary sourcePrimary sources — vendor advisories, patches and trackers. Where our summary and a reference disagree, the reference wins.

Primary sources

Practitioner notes

Contributed

Peer-ranked notes from engineers who’ve handled CVE-2026-2360 in production — separate from our analysis above.

No notes yet

Be the first to add a field note for this CVE — a mitigation you’ve verified, a version caveat, or a link to a working fix. Sign in above to contribute.

What this is

A place for practitioners to share what actually worked: a mitigation you’ve tested, a configuration change, a version- or environment-specific caveat, or a link to a verified patch. The most useful notes rise to the top as peers upvote them, so the signal stays high.

What belongs here
  • Verified mitigations, workarounds, and config changes
  • Version or environment caveats, and links to real fixes
  • No weaponised exploit code, or anything meant to cause harm
  • No spam, self-promotion, credentials, or personal data