Skip to main content
QUIETLYTIC
Vulnerability

2 PostgreSQL Anonymizer CVEs (CVE-2026-19634)

Two more PostgreSQL Anonymizer vulnerabilities (CVE-2026-19634, CVE-2026-83534) let a table owner or masked user reach superuser-level code execution through the extension's import and parallel-anonymization functions.

CVE-2026-19634
Threat Level
MEDIUM
CVSS
6.4
Status
Monitored
Confidence
Medium
Affected Products
PostgreSQL Anonymizer

Full CVE Roster

All 2 CVEs from this release, ready to paste into a tracker, ticket, or SIEM search.

CVE ID Title CVSS Severity KEV
CVE-2026-19634 — 6.4 medium
CVE-2026-83534 — 6.4 medium

Alongside CVE-2026-19633 (covered separately), two more PostgreSQL Anonymizer vulnerabilities — CVE-2026-19634 and CVE-2026-83534 — were disclosed in the same period, both fixed by upgrading the extension.

CVE-2026-19634: SQL injection via crafted import files

Per NVD’s description, a user can craft a malicious JSON document containing specially crafted object names. If a superuser subsequently calls anon.import_database_rules() or anon.import_roles_rules() against that document, the embedded malicious code executes with superuser privileges. CVSS 3.1 base 6.4 (medium).

CVE-2026-83534: privilege escalation via parallel anonymization

Per NVD’s description, the anon.anonymize_database_parallel() function allows the owner of a table — not necessarily a superuser — to run arbitrary code with superuser privilege. CVSS 3.1 base 6.4 (medium).

Fix and affected versions

CVE-2026-19634 is fixed in PostgreSQL Anonymizer 3.1.4 and later. CVE-2026-83534 requires the later 3.2.0 and later. Deployments should target 3.2.0 or newer to close both gaps at once, alongside CVE-2026-19633’s fix.

What we don’t yet have

Both records trace to the project’s own GitLab issue tracker via NVD; no CISA KEV listing or independent second-source corroboration is present, so confidence is medium.

Why this matters

Between these two CVEs and CVE-2026-19633, PostgreSQL Anonymizer has had three distinct privilege-escalation-adjacent findings in the same disclosure window, all sharing a common theme: an operation performed by a lower-privileged role (a masked user, a table owner) can reach code execution at superuser level through the extension’s own masking or import machinery. Any deployment using this extension to safely delegate access to lower-trust roles should upgrade to 3.2.0 or later as a single remediation for all three.

Frequently Asked Questions

What are CVE-2026-19634 and CVE-2026-83534? Two CVSS 6.4 medium-severity vulnerabilities in PostgreSQL Anonymizer: a SQL injection reachable through crafted import files (19634), and a privilege escalation letting a table owner reach superuser code execution via parallel anonymization (83534).

Which version fixes these vulnerabilities? PostgreSQL Anonymizer 3.1.4 fixes CVE-2026-19634; 3.2.0 fixes CVE-2026-83534. Use 3.2.0 or later for both.

Are these vulnerabilities being actively exploited? No evidence of active exploitation has been reported as of this writing; neither is listed in CISA’s KEV catalog.


Data sourced from the National Vulnerability Database (NVD) and PostgreSQL Anonymizer’s GitLab issue tracker, aggregated September 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 PostgreSQL Anonymizer (GitLab)

Related intelligence


Analyst tools