To remediate this issue, users should upgrade to version 2.1.2 or later.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 24 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 24 Sep 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | pgcollection is an open source extension to PostgreSQL. A type confusion issue in AWS pgcollection 2.0.0 through 2.1.1 might allow an authenticated remote user to execute arbitrary code as the postgres operating system user via crafted SQL statements that rely on mismatched type metadata in collection value retrieval and array conversion functions. To remediate this issue, users should upgrade to version 2.1.2 or later. | |
| Title | Type confusion in AWS pgcollection allows remote code execution | |
| First Time appeared |
Aws
Aws pgcollection |
|
| Weaknesses | CWE-843 | |
| CPEs | cpe:2.3:a:aws:pgcollection:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Aws
Aws pgcollection |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: AMZN
Published:
Updated: 2026-09-24T19:26:14.740Z
Reserved: 2026-09-23T18:18:05.982Z
Link: CVE-2026-96883
Updated: 2026-09-24T19:26:11.675Z
Status : Received
Published: 2026-09-24T20:17:35.240
Modified: 2026-09-24T20:17:35.240
Link: CVE-2026-96883
No data.
OpenCVE Enrichment
No data.
