CVE-2026-2360
Official description Straight from the sourceThe vendor's or NVD's own wording, published unedited. Authoritative, but often terse — it says what broke, rarely what to do.
NVD · uneditedPostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a custom operator in the public schema and place malicious code in that operator. This operator will later be executed with superuser privileges when the extension is created. The risk is higher with PostgreSQL 14 or with instances upgraded from PostgreSQL 14 or a prior version. With PostgreSQL 15 and later, the creation permission on the public schema is revoked by default and this exploit can only be achieved if a superuser adds a new schema in her/his own search_path and grants the CREATE privilege on that schema to untrusted users, both actions being clearly discouraged by the PostgreSQL documentation. The problem is resolved in PostgreSQL Anonymizer 3.0.1 and further versions
Technical summary Written by usOur analysis, written from the advisory, the CVSS vector and the affected-version data. It adds context the advisory leaves out, and never invents facts that are not in the source.
dbcve analysis · high confidencePostgreSQL Anonymizer before 3.0.1 allows untrusted users to escalate to superuser privileges by creating a malicious custom operator in the public schema. When the extension is created, it executes this operator with superuser privileges. PostgreSQL 14 or upgraded instances are at higher risk, while PostgreSQL 15+ has safer defaults.
Verify against the referenced sources before acting — the references below are authoritative for this CVE, this summary is not.
CVSS breakdown How the score is builtThe industry scoring standard. It rates how the flaw is reached, what it takes to exploit, and what an attacker gains — the score is derived from those, not the other way round.
From the vector- Attack vector
- Network
- Complexity
- High
- Privileges
- High
- User interaction
- None
- Scope
- Changed
- Confidentiality
- High
- Integrity
- High
- Availability
- High
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Am I affected? How to checkSteps we derive from the advisory and the affected-version data, so you can decide whether this CVE reaches your setup. They are a guide, not a scan — your own configuration is the authority.
dbcve checksWork through these to decide whether this CVE applies to you.
-
Verify PostgreSQL Anonymizer extension is installedQuery pg_extension catalog: SELECT extname, extversion FROM pg_extension WHERE extname = 'anon';Affected if No rows returned means the extension is not installed and the vulnerability does not apply.
-
Determine installed PostgreSQL Anonymizer versionIf the extension exists, run: SELECT anon.version(); or check pg_extension.extversion for the 'anon' extension.Affected if Version is below 3.0.1 - the vulnerability is present in this installation.
-
Check PostgreSQL server versionRun: SELECT version(); or SHOW server_version;Affected if Running PostgreSQL 14 or any upgraded instance increases the risk profile significantly.
-
Inspect custom operators in the public schemaQuery pg_operator for operators in public schema created by non-superusers: SELECT proname, pronamespace::regnamespace FROM pg_proc JOIN pg_namespace ON pronamespace = oid WHERE pronamespace = 'public'::regnamespace AND proowner != (SELECT oid FROM pg_roles WHERE rolname = 'postgres');Affected if Any custom operators exist in public schema created by untrusted users - these could be malicious.
-
Review current search_path settingRun: SHOW search_path;Affected if Search_path includes 'public' without explicit schema qualification allows operators in public schema to be resolved automatically.
You are affected if PostgreSQL Anonymizer version is below 3.0.1 AND untrusted users can create or have created custom operators in the public schema, especially on PostgreSQL 14 or upgraded instances.
Generated from the published advisory. Verify against your own configuration.
Remediation Closing itWhat it takes to close this. Where a vendor fix exists we point at it; where none exists we say so plainly, and can build one. Effort estimates are scoped from the advisory, not from your codebase.
dbcve · scopedUpgrade PostgreSQL Anonymizer to version 3.0.1 or later. For PostgreSQL 14 or upgraded instances, additionally audit the database for suspicious operators in the public schema and review search_path configurations.
PostgreSQL Anonymizer 3.0.1 or later
- 1. Identify the current installed version of the PostgreSQL Anonymizer extension using psql: SELECT * FROM pg_extension WHERE extname = 'anon';
- 2. If the installed version is earlier than 3.0.1, upgrade the PostgreSQL Anonymizer extension to version 3.0.1 or later
- 3. If using PostgreSQL 14 or an instance upgraded from PostgreSQL 14 or prior, ensure you are also on PostgreSQL Anonymizer 3.0.1+ which contains the fix
- 4. After upgrading, verify the new version is active: SELECT anon.extension_version();
- 5. As a security best practice, ensure the public schema does not have CREATE permission granted to untrusted users (this is default in PostgreSQL 15+)
Generated from the published advisory — verify against the referenced sources before acting.
- Consultation3.0 h
- Implementation2.0 h
- Testing3.0 h
- Review / QA2.0 h
An estimate, not a bill — we confirm scope with you before any work starts. Need it this week? Rush from $2,832.
Scan for this in your stack
Free · runs locallyCheck whether your project pulls in CVE-2026-2360 — or any other known-vulnerable package — straight from your lock files. Free and open source; it runs locally and uploads nothing.
References Go to the primary sourcePrimary sources — vendor advisories, patches and trackers. Where our summary and a reference disagree, the reference wins.
Primary sourcesPractitioner notes
ContributedPeer-ranked notes from engineers who’ve handled CVE-2026-2360 in production — separate from our analysis above.
The advisory tells you what broke. It rarely tells you what actually worked. If you’ve dealt with this one, that detail is what the next engineer is searching for.
- The version that genuinely resolved it — not the one the vendor claimed
- A config change or rule that shut the vector down
- A gotcha in the upgrade path that cost you an afternoon
No notes yet
Be the first to add a field note for this CVE — a mitigation you’ve verified, a version caveat, or a link to a working fix. Sign in above to contribute.
A place for practitioners to share what actually worked: a mitigation you’ve tested, a configuration change, a version- or environment-specific caveat, or a link to a verified patch. The most useful notes rise to the top as peers upvote them, so the signal stays high.
- Verified mitigations, workarounds, and config changes
- Version or environment caveats, and links to real fixes
- No weaponised exploit code, or anything meant to cause harm
- No spam, self-promotion, credentials, or personal data