PostgreSQL Anonymizer privilege escalation flaw patched
A privilege escalation vulnerability in PostgreSQL Anonymizer versions before 3.1 allows attackers to elevate privileges; patches available.
CERT-FR has published an advisory regarding a privilege escalation vulnerability affecting PostgreSQL Anonymizer versions prior to 3.1. The flaw, tracked as CVE-2026-9617, enables an attacker to elevate their privileges within affected systems.
PostgreSQL Anonymizer is an extension that provides data masking and anonymization capabilities for PostgreSQL databases. The vulnerability represents a significant security risk for organizations using older versions of the extension, as privilege escalation flaws can allow attackers to gain unauthorized administrative access to database systems.
PostgreSQL has released version 3.1 of the Anonymizer extension to address this vulnerability. Organizations running affected versions should prioritize patching to mitigate the risk of exploitation.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0718
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free