CVE-2026-83534 MEDIUM

CVE-2026-83534: PostgreSQL Anonymizer: Privilege escalation to superuser via anon.anonymize_database_parallel()

Vendor Dalibo
Product PostgreSQL Anonymizer
Weakness CWE-250
Published September 6, 2026
Last update September 6, 2026

CVSS base score

6.4/10
Attack vector Network
Attack complexity High
Privileges required High
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

PostgreSQL Anonymizer contains a vulnerability in the anon.anonymize_database_parallel() function that allows the owner of a table to run arbitrary code with superuser privilege. The issue is fixed in PostgreSQL Anonymizer 3.2.0 and later versions

Key dates

02Disclosure timeline

September 6, 2026 CVE published