CVE-2026-50736

CRITICAL CVSS 4.0: 9.0 EPSS 0.41%
Updated Aug 24, 2026
PostgreSQL
Parameter Value
CVSS 9.0 (CRITICAL)
Affected Versions 2.0.0 — 2.4.8
Fixed In 2.4.8
Type CWE-89 (SQL Injection)
Vendor PostgreSQL
Public PoC No

The pglogical queue mechanism, used to convey out-of-band commands such as replicated DDL from a publisher to a subscriber, executes message payloads on the subscriber at the privilege level of the apply worker, which is equivalent to a PostgreSQL superuser in default installations. A party acting as the publisher can send crafted queue messages that cause arbitrary SQL to be executed on the subscriber as superuser, escalating from a role permitted to use pglogical to full superuser and breaking the isolation between tenants in shared deployments. To exploit the issue an attacker must be able to direct a subscription at an endpoint they control.

In default installations this requires privileges normally reserved for a superuser, so the issue is most relevant to managed deployments where the ability to create subscriptions has been delegated to non-superuser roles.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
High
Difficult to exploit
Attack Requirements
Present
Additional conditions required
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
High
Complete denial of service

CVSS Vector v4.0

Weakness Type (CWE)

Vulnerable Products 1

Configuration From (including) Up to (excluding)
Enterprisedb Pglogical
cpe:2.3:a:enterprisedb:pglogical:*:*:*:*:*:postgresql:*:*
2.0.0 2.4.8