Skip to content
cve — cve-2026-6471

grep -rl "CVE-2026-6471" ./articles

CVE-2026-6471

CVE-2026-6471 lets any account holding PostgreSQL's REPLICATION attribute load an arbitrary library as a logical decoding plugin and run code as the postgres user. It has been there since logical decoding shipped in 9.4 in 2014, and REPLICATION is the privilege every CDC pipeline in your estate already has.

1 article — 2026-09-07

Authoritative record

Root Notes reports on this identifier; it does not maintain it. For the vendor advisory, the affected versions and the scoring, NVD and MITRE hold the primary records.

Our coverage

REPLICATION was never a read-only privilege. For twelve years it was a shell

2026-09-07Security

CVE-2026-6471 lets any account holding PostgreSQL's REPLICATION attribute load an arbitrary library as a logical decoding plugin and run code as the postgres user. It has been there since logical decoding shipped in 9.4 in 2014, and REPLICATION is the privilege every CDC pipeline in your estate already has.

../cve — every identifier we have covered