CVE-2026-11945 - PostgreSQL Anonymizer: SQL injection in the rules import functions - Mehmet Ince @mdisec - Vulnerability Researcher | Building security products | Security Advisor | Amateur Muay Thai fighter Skip to content Posts CVE INDEX About Me X LinkedIn YouTube GitHub CVE-2026-11945 – PostgreSQL Anonymizer: SQL injection in the rules import functions Jun 18, 2026 Description PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a JSON document and placing malicious code inside a particular key-value pair. If a superuser calls the import_database_rules() or import_roles_rules() functions, the malicious code is executed with superuser privileges. The problem is resolved in PostgreSQL Anonymizer 3.1.1 and further versions Vulnerability Information Product / Framework: PostgreSQL Anonymizer Vendor Domain: www.postgresql.org Vulnerability Type: SQL Injection CVE Details: View Full CVE Details → You may also enjoy… The Story of a Perfect Exploit Chain: Six Bugs That Looked Harmless Until They Became Pre-Auth RCE in a Security Appliance Jan 2026 Inside PostHog: How SSRF, a ClickHouse SQL Escaping 0day, and Default PostgreSQL Credentials Formed an RCE Chain (ZDI-25-099, ZDI-25-097, ZDI-25-096) Dec 2025 The Chessboard of Security: Insights on Product Development and Vulnerabilities from a Hacker Perspective Nov 2025 Digital Cosmos: A Journey Through the Galaxy of Vulnerabilities Oct 2025 CVE-2021-3825 | LiderAhenk 0day – All your PARDUS Clients Belongs To Me Dec 2021 Posts CVE INDEX About Me Search Search