CVE-2026-50737
EnterpriseDB pglogical
When applying replicated changes for a row that is missing one or more columns, pglogical evaluates the affected table's default expressions on the subscriber. Because the apply worker runs at a privilege level equivalent to a PostgreSQL superuser in default installations, any function invoked by such a default expression also runs at that privilege. A party acting as the publisher can use this path to cause functions to be executed on the subscriber as superuser, escalating from a role permitted to use pglogical to full superuser. This is a second, independent path to the same superuser es...
- CVSS
- 9
- EPSS
- - - percentile
- CISA KEV
- Not listed
- Published
- 2026.07.29