{"id":"CVE-2026-96883","title":"pgcollection is an open source extension to PostgreSQL","summary":"pgcollection is an open source extension to PostgreSQL. A type confusion issue in AWS pgcollection 2.0.0 through 2.1.1 might allow an authenticated remote user to execute arbitrary code as the postgres operating system user via crafted S…","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-843"],"vendor":"AWS","product":"pgcollection","affected":["pgcollection >= 2.0.0 <= 2.1.1"],"published":"2026-09-24","updated":"2026-09-24","sourceUpdated":"2026-09-24T20:17:35.240","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-96883","references":[{"url":"https://aws.amazon.com/security/security-bulletins/2026-118-aws/","label":"ff89ba41-3aa1-4d27-914a-91399e9639e5"},{"url":"https://github.com/aws/pgcollection/releases/tag/v2.1.2","label":"ff89ba41-3aa1-4d27-914a-91399e9639e5"},{"url":"https://github.com/aws/pgcollection/security/advisories/GHSA-g539-cj32-hv6r","label":"ff89ba41-3aa1-4d27-914a-91399e9639e5"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-24T19:26:07.145601Z"},"ingestedAt":"2026-09-24T19:50:30.730Z","slug":"CVE-2026-96883","body":"## Overview\n\npgcollection is an open source extension to PostgreSQL. A type confusion issue in AWS pgcollection 2.0.0 through 2.1.1 might allow an authenticated remote user to execute arbitrary code as the postgres operating system user via crafted SQL statements that rely on mismatched type metadata in collection value retrieval and array conversion functions.\n\n\n\nTo remediate this issue, users should upgrade to version 2.1.2 or later.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":48.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}