PostgreSQL Anonymizer contains a vulnerability in the anon.anonymize_database_parallel() function that allows the owner of a table to run arbitrary code with superuser privilege. The issue is fixed in PostgreSQL Anonymizer 3.2.0 and later versions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
Set anon.static_masking to FALSE to disable the feature
References
| Link | Providers |
|---|---|
| https://gitlab.com/dalibo/postgresql_anonymizer/-/issues/666 |
|
History
Sun, 06 Sep 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dalibo
Dalibo postgresql Anonymizer |
|
| Vendors & Products |
Dalibo
Dalibo postgresql Anonymizer |
Sun, 06 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PostgreSQL Anonymizer contains a vulnerability in the anon.anonymize_database_parallel() function that allows the owner of a table to run arbitrary code with superuser privilege. The issue is fixed in PostgreSQL Anonymizer 3.2.0 and later versions | |
| Title | PostgreSQL Anonymizer: Privilege escalation to superuser via anon.anonymize_database_parallel() | |
| Weaknesses | CWE-250 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: PostgreSQL
Published:
Updated: 2026-09-06T15:25:41.341Z
Reserved: 2026-08-31T16:51:52.845Z
Link: CVE-2026-83534
No data.
Status : Received
Published: 2026-09-06T16:16:50.753
Modified: 2026-09-06T16:16:50.753
Link: CVE-2026-83534
No data.
OpenCVE Enrichment
Updated: 2026-09-06T17:00:05Z
Weaknesses