---
id: CVE-2026-14673
title: >-
  Untrusted search path in PostgreSQL amcheck allows a grantee of amcheck
  function EXECUTE privilege to execute arbitrary functions as the owners of
  expression indexes that depend on the search path, via setting a hostile
  search path befor…
summary: >-
  Untrusted search path in PostgreSQL amcheck allows a grantee of amcheck
  function EXECUTE privilege to execute arbitrary functions as the owners of
  expression indexes that depend on the search path, via setting a hostile
  search path befor…
severity: low
cvss: 3.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N'
cwe:
  - CWE-426
vendor: postgresql
product: postgresql
affected:
  - 'postgresql >= 14.0, < 14.24'
  - 'postgresql >= 15.0, < 15.19'
  - 'postgresql >= 16.0, < 16.15'
  - 'postgresql >= 18.0, < 18.5'
patched:
  - postgresql 18.5
published: '2026-08-13'
updated: '2026-08-29'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-14673'
references:
  - url: 'https://www.postgresql.org/support/security/CVE-2026-14673/'
    label: f86ef6dc-4d3a-42ad-8f28-e6d5547a5007
tags:
  - nvd
epss: 0.00174
epssPercentile: 0.07161
ingestedAt: '2026-08-29T23:43:53.293Z'
---

## Overview

Untrusted search path in PostgreSQL amcheck allows a grantee of amcheck function EXECUTE privilege to execute arbitrary functions as the owners of expression indexes that depend on the search path, via setting a hostile search path before calling the amcheck function.  Within major versions 18, 16, 15, and 14, minor versions before PostgreSQL 18.6, 16.15, 15.19, and 14.24 are affected.  PostgreSQL 17 is unaffected.

## Affected

- `postgresql >= 14.0, < 14.24`
- `postgresql >= 15.0, < 15.19`
- `postgresql >= 16.0, < 16.15`
- `postgresql >= 18.0, < 18.5`

## Remediation

Upgrade past the affected range:

- `postgresql 18.5`
