Alongside CVE-2026-19633 (covered separately), two more PostgreSQL Anonymizer vulnerabilities — CVE-2026-19634 and CVE-2026-83534 — were disclosed in the same period, both fixed by upgrading the extension.
CVE-2026-19634: SQL injection via crafted import files
Per NVD’s description, a user can craft a malicious JSON document containing specially crafted object names. If a superuser subsequently calls anon.import_database_rules() or anon.import_roles_rules() against that document, the embedded malicious code executes with superuser privileges. CVSS 3.1 base 6.4 (medium).
CVE-2026-83534: privilege escalation via parallel anonymization
Per NVD’s description, the anon.anonymize_database_parallel() function allows the owner of a table — not necessarily a superuser — to run arbitrary code with superuser privilege. CVSS 3.1 base 6.4 (medium).
Fix and affected versions
CVE-2026-19634 is fixed in PostgreSQL Anonymizer 3.1.4 and later. CVE-2026-83534 requires the later 3.2.0 and later. Deployments should target 3.2.0 or newer to close both gaps at once, alongside CVE-2026-19633’s fix.
What we don’t yet have
Both records trace to the project’s own GitLab issue tracker via NVD; no CISA KEV listing or independent second-source corroboration is present, so confidence is medium.
Why this matters
Between these two CVEs and CVE-2026-19633, PostgreSQL Anonymizer has had three distinct privilege-escalation-adjacent findings in the same disclosure window, all sharing a common theme: an operation performed by a lower-privileged role (a masked user, a table owner) can reach code execution at superuser level through the extension’s own masking or import machinery. Any deployment using this extension to safely delegate access to lower-trust roles should upgrade to 3.2.0 or later as a single remediation for all three.
Frequently Asked Questions
What are CVE-2026-19634 and CVE-2026-83534? Two CVSS 6.4 medium-severity vulnerabilities in PostgreSQL Anonymizer: a SQL injection reachable through crafted import files (19634), and a privilege escalation letting a table owner reach superuser code execution via parallel anonymization (83534).
Which version fixes these vulnerabilities? PostgreSQL Anonymizer 3.1.4 fixes CVE-2026-19634; 3.2.0 fixes CVE-2026-83534. Use 3.2.0 or later for both.
Are these vulnerabilities being actively exploited? No evidence of active exploitation has been reported as of this writing; neither is listed in CISA’s KEV catalog.
Data sourced from the National Vulnerability Database (NVD) and PostgreSQL Anonymizer’s GitLab issue tracker, aggregated September 2026. See more vulnerability intelligence.