By vendor
Dalibo vulnerabilities
Known CVEs affecting Dalibo products, prioritized by severity, with SEC.co remediation and detection guidance.
1 published vulnerability
- CVE-2026-11945MEDIUM 6.4
PostgreSQL Anonymizer, an extension for PostgreSQL that helps mask sensitive data, contains a privilege escalation vulnerability. An authenticated attacker with standard user privileges can craft a malicious JSON document and trick a database superuser into importing it using specific functions (import_database_rules() or import_roles_rules()). When the superuser processes the JSON, hidden malicious code executes with superuser-level privileges, giving the attacker complete database access. This requires both user authentication and superuser action, limiting the immediate risk but creating a serious supply-chain or trusted-user threat.