EnterpriseDB pglogical是美国EnterpriseDB公司开源的一款数据库逻辑复制扩展。 EnterpriseDB pglogical 2.4.8之前版本存在权限许可和访问控制问题漏洞,该漏洞源于处理缺失列的行时默认表达式在超级用户权限下执行,导致攻击者可将角色从允许使用pglogical升级为完全超级用户。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| EnterpriseDB | pglogical | 2< 2.4.8 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| EnterpriseDB | pglogical | 2 ~ 2.4.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-50736 | 9.0 CRITICAL | EnterpriseDB pglogical SQL注入漏洞 |
| CVE-2026-50738 | 7.7 HIGH | EnterpriseDB pglogical 资源管理错误漏洞 |
| CVE-2026-50735 | 6.1 MEDIUM | EnterpriseDB pglogical 缓冲区错误漏洞 |
No comments yet