CVE-2026-11945

HIGH WAF: High
CVSS 7.5 Published: 2026-06-11
CWE-89

PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a JSON document and placing malicious code inside a particular key-value pair. If a superuser calls the import_database_rules() or import_roles_rules() functions, the malicious code is executed with superuser privileges. The problem is resolved in PostgreSQL Anonymizer 3.1.1 and further versions

WAF Coverage Analysis

SQL Injection High WAF Coverage

OWASP: A03:2021 Injection

942xxx - SQL Injection

Affected Software

VendorProductVersion
dalibopostgresql_anonymizerup to 3.1.1

References

  • gitlab.com (Exploit, Issue Tracking, Patch, Vendor Advisory)
Back to CVE Database