CVE-2026-50736 Details
Description
The pglogical queue mechanism, used to convey out-of-band commands such as replicated DDL from a publisher to a subscriber, executes message payloads on the subscriber at the privilege level of the apply worker, which is equivalent to a PostgreSQL superuser in default installations. A party acting as the publisher can send crafted queue messages that cause arbitrary SQL to be executed on the subscriber as superuser, escalating from a role permitted to use pglogical to full superuser and breaking the isolation between tenants in shared deployments. To exploit the issue an attacker must be able to direct a subscription at an endpoint they control. In default installations this requires privileges normally reserved for a superuser, so the issue is most relevant to managed deployments where the ability to create subscriptions has been delegated to non-superuser roles.
A vulnerability in the pglogical queue mechanism allows for privilege escalation to superuser on PostgreSQL subscribers. This issue arises because the queue mechanism executes messages at the privilege level of the apply worker, which is superuser by default. An attacker controlling a publisher can send crafted messages that execute arbitrary SQL as superuser on the subscriber, undermining tenant isolation in shared deployments. Exploitation requires directing a subscription to an endpoint under the attacker's control, a capability typically reserved for superusers but potentially available to non-superuser roles in managed deployments.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.enterprisedb.com/docs/security/advisories/cve202650736/ | EnterpriseDB Corporation | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-89 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | EnterpriseDB Corporation |
Affected Products
| Product | Versions |
|---|---|
| enterprisedb pglogical | >= 2.0.0, < 2.4.8 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 24, 2026 | Initial Analysis | [email protected] |
| Jul 28, 2026 | CVE Modified | CISA-ADP |
| Jul 28, 2026 | New CVE Received | EnterpriseDB Corporation |