CVE-2026-19633
HIGH
NVD
CVSS Score
8.8
Severity
HIGH
Published
Sep 06, 2026
Vendor
unknown
Description
PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to execute arbitrary code by abusing operators, domain casts, or view subqueries that carry untrusted expressions. When these objects are evaluated in the context of the extensionβs masking mechanisms, the malicious code can run with elevated privileges. The issue is fixed in PostgreSQL Anonymizer 3.1.4 and later versions