The PostgreSQL fuzzystrmatch bug needs a database login
CVE-2026-15742 can run code as the PostgreSQL operating-system user. The vendor score is 8.8 and the vector requires a database account. Fixed builds shipped on 13 August 2026. A public PoC path exists. CISA has not listed it.
Published 5 Oct 2026
What happened
On 13 August 2026 the PostgreSQL project published CVE-2026-15742 with the fixes. Integer wraparound in the fuzzystrmatch contrib module lets a user direct writes across a large range of addresses by sending extreme inputs to levenshtein() or levenshtein_less_equal(). The project says that can execute arbitrary code as the operating-system user running the database. NVD published the same text the same day. The score is 8.8.
Who is affected
The branches in the advisory are PostgreSQL 18 before 18.6, 17 before 17.11, 16 before 16.15, 15 before 15.19, and 14 before 14.24. The component line on the advisory is the contrib module. Red Hat’s note on the same CVE says the risk is present when fuzzystrmatch is installed, and that it is not enabled by default in Red Hat’s PostgreSQL builds. A server that has never created the extension is outside that description.
The CVSS vector is AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. Network access is not the same thing as no account. The score requires low privileges, which here means a database login that can call those functions.
What is confirmed
The fixed versions and the 13 August 2026 date are in the project table. The finder credited on the CVE record is Ben Morris of Claude and Anthropic Research. CWE-190 is the weakness. A public path for this CVE is present in the kmkz/Exploits repository, so the ThreatWire status is PoC Available. CISA’s Known Exploited Vulnerabilities catalog does not list it.
What is not confirmed
The alert calls the bug a memory-corruption vulnerability that can lead to code execution. The vendor text supports code execution as the database OS user. It does not say the bug is reachable with no database account, and it does not say attacks are underway. This record is not Active Exploitation and not a 0-day. The fix date is the publication date of the advisory.
What to do
Move each supported branch to 18.6, 17.11, 16.15, 15.19, or 14.24. If the extension is not required, removing it is the mitigation Red Hat describes for its packages, with a restart if the package removal needs one. The inputs used to reach the wraparound are not reprinted here.
Sources: the PostgreSQL page for CVE-2026-15742, NVD, and the public repository path linked from the CVE record.
Related CVEs
- CVE-2026-15742 — PostgreSQL fuzzystrmatch integer wraparound