CVE-2026-19633 is a high-severity (CVSS 3.1 base 8.8) privilege-escalation vulnerability in PostgreSQL Anonymizer, an extension that masks sensitive data for non-privileged database users.
What the vulnerability does
Per NVD’s description, PostgreSQL Anonymizer allows unprivileged masked users to execute arbitrary code by abusing operators, domain casts, or view subqueries that carry untrusted expressions. When the extension’s own masking mechanisms evaluate these objects, the malicious code embedded inside them runs with the elevated privileges the masking process itself holds — turning the very mechanism designed to protect data from unprivileged users into a path for those users to escalate their own access.
The CVSS vector (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) shows a network-reachable, low-complexity flaw requiring low privileges (consistent with the “masked user” role the extension itself grants) and no user interaction, with full confidentiality, integrity, and availability impact — consistent with arbitrary code execution at elevated privilege.
Fix and affected versions
Fixed in PostgreSQL Anonymizer 3.1.4 and later, per NVD’s reference to the project’s own GitLab issue tracker.
What we don’t yet have
This record traces to a single GitLab issue reference via NVD; no CISA KEV listing or independent second-source corroboration is present, so confidence is medium.
Why this matters
PostgreSQL Anonymizer exists specifically to let organizations grant broader database access to masked, lower-trust users (analysts, contractors, test environments) while still protecting underlying sensitive data. A privilege-escalation bug in the masking layer itself undermines that entire trust model — any deployment relying on this extension to safely expose masked data to less-trusted database roles should prioritize upgrading to 3.1.4 before continuing to rely on that isolation boundary.
Frequently Asked Questions
What is CVE-2026-19633? A CVSS 8.8 high-severity vulnerability in PostgreSQL Anonymizer allowing masked (lower-privilege) database users to execute arbitrary code with elevated privileges by abusing operators or subqueries evaluated during masking.
Which version fixes CVE-2026-19633? PostgreSQL Anonymizer 3.1.4 and later.
Is CVE-2026-19633 being actively exploited? No evidence of active exploitation has been reported as of this writing; it is not listed in CISA’s KEV catalog.
Data sourced from the National Vulnerability Database (NVD), aggregated September 2026. See more vulnerability intelligence.