VulnWatch VulnWatch
← Back to dashboard
High nvd · CVE-2026-16239

CVE-2026-16239: Type confusion in PostgreSQL "portal"/cursor lifecycle allows a user to execute arbitrary code as the operating system u

Published Aug 13, 2026 CVSS 8.8

Type confusion in PostgreSQL "portal"/cursor lifecycle allows a user to execute arbitrary code as the operating system user running the database, via re-creation of a cursor or other portal with different types. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.

Affected AI Products

cursor
Get the weekly digest. Every Monday: top AI security stories of the week. Free.