CVE-2025-59470

Publication date

2026-01-08 16:18:20

Family

hackerone

State

PUBLISHED

Description

This vulnerability allows a Backup Operator to perform remote code execution (RCE) as the postgres user by sending a malicious interval or order parameter.