Beveiligingsadvies

CVE-2026-16503

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-07-31 15:18:33
Laatst bijgewerkt 2026-08-03 17:13:26
Toegewezen door certcc
CVSS-score 9.1
Status PUBLISHED

Beschrijving

Deployment of the VPS.org one-click Supabase template deploys a PostgreSQL instance that is published on all interfaces (0.0.0.0:5432) with a default database password set to "postgres". Because Docker installs its own iptables rules, this exposure bypasses a standard host UFW configuration.