---
id: CVE-2026-83534
title: >-
  PostgreSQL Anonymizer contains a vulnerability in the
  anon.anonymize_database_parallel() function that allows the owner of a table
  to run arbitrary code with superuser privilege
summary: >-
  PostgreSQL Anonymizer contains a vulnerability in the
  anon.anonymize_database_parallel() function that allows the owner of a table
  to run arbitrary code with superuser privilege. The issue is fixed in
  PostgreSQL Anonymizer 3.2.0 and late…
severity: medium
cvss: 6.4
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-250
vendor: DALIBO
product: PostgreSQL Anonymizer
affected:
  - postgresql_anonymizer >= 1 < 3.2.0
published: '2026-09-06'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T05:18:19.027'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-83534'
references:
  - url: 'https://gitlab.com/dalibo/postgresql_anonymizer/-/issues/666'
    label: f86ef6dc-4d3a-42ad-8f28-e6d5547a5007
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-83534.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-83534'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-83534'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-08T10:29:23.582874Z'
epss: 0.00192
epssPercentile: 0.07802
ingestedAt: '2026-09-07T06:06:09.551Z'
---

## Overview

PostgreSQL Anonymizer contains a vulnerability in the anon.anonymize_database_parallel() function that allows the owner of a table to run arbitrary code with superuser privilege. The issue is fixed in PostgreSQL Anonymizer 3.2.0 and later versions

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **Red Hat VEX** · updated 2026-09-07 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-83534.json)
