CVE-2026-19633
Last modified
CVE-2026-19633 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to execute arbitrary code by abusing operators, domain casts, or view subqueries that carry untrusted expressions. When these objects are evaluated in the context of the extension’s masking mechanisms, the malicious code can run with elevated privileges. EPSS estimates a 0.36% chance of exploitation in the next 30 days.
Description
PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to execute arbitrary code by abusing operators, domain casts, or view subqueries that carry untrusted expressions. When these objects are evaluated in the context of the extension’s masking mechanisms, the malicious code can run with elevated privileges. The issue is fixed in PostgreSQL Anonymizer 3.1.4 and later versions
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| DALIBO | PostgreSQL Anonymizer | >= 1, < 3.1.4 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-19633?
How severe is CVE-2026-19633?
How do I fix CVE-2026-19633?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-19626A remote code execution vulnerability exists in Tenable Secu…9.9
- CVE-2026-19628A command injection vulnerability exists in Tenable Security…7.2
- CVE-2026-19629A privilege escalation vulnerability exists in Tenable Secur…8.1
- CVE-2026-1963A vulnerability was found in WeKan up to 8.20. This affects …9.8
- CVE-2026-19631A SQL injection vulnerability exists in Security Center that…4.9
- CVE-2026-19632The TranslatePress – Translate Multilingual sites with AI Tr…9.8
- CVE-2026-19634PostgreSQL Anonymizer contains a SQL injection vulnerability…6.4
- CVE-2026-19635A local privilege escalation vulnerability exists in Securit…8.8
- CVE-2026-19636An issue was identified in which CSRF tokens were generated …5.3
- CVE-2026-19639An improper access control vulnerability exists where an aut…4.3
- CVE-2026-1964A vulnerability was determined in WeKan up to 8.20. This imp…5.3
- CVE-2026-19640On affected platforms running Arista EOS, an authenticated u…4.2
Are you affected by CVE-2026-19633?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
