CVE-2026-65314 MEDIUM

CVE-2026-65314: Electric Postgres Sync Excluded-Column Value Inference via Subset Where Clauses

Vendor Electricsql
Product Electric Postgres Sync
Weakness CWE-203
Published July 21, 2026
Last update July 22, 2026

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Electric Postgres Sync versions below 1.6.10 contains an information disclosure vulnerability that allows attackers to infer the values of excluded columns by crafting subset where clause conditions against shape responses. Attackers can observe whether subset where conditions match rows to deduce sensitive field data even though those columns are not returned in shape responses, bypassing column-based access restrictions.

Key dates

02Disclosure timeline

July 21, 2026 CVE published
July 22, 2026 Record updated