CVE-2026-83534
6.4
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H
Summary
PostgreSQL Anonymizer contains a vulnerability in the anon.anonymize_database_parallel() function that allows the owner of a table to run arbitrary code with superuser privilege. The issue is fixed in PostgreSQL Anonymizer 3.2.0 and later versions
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| DALIBO | PostgreSQL Anonymizer | 1 < 3.2.0 | affected |
Weaknesses
- CWE-250: Execution with Unnecessary Privileges
Workarounds
Set anon.static_masking to FALSE to disable the feature
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.