Blog
Insights on software development, security, and technology from our team.

A PostgreSQL backup account can now run code on your server. Patch CVE-2026-6471.
PostgreSQL patched CVE-2026-6471, a flaw present since 2014 that lets a low-privilege REPLICATION account load arbitrary code and take over the database host. The official severity is 7.2, not critical, because it needs an account that backup tools, replicas and CDC pipelines all use. Here is how to patch, what the new output_plugin_libraries allowlist changes, and which service accounts to audit first.