← back
CVE-2025-59470criticalCWE-77

CVE-2025-59470

48Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 9epss 1.5%
from disclosure to weapon33 days
Published on NVDJan 8
1st PoC+33d
exploitation probability
1.5%top 29% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
In short

A Backup Operator can run malicious code on the server as the postgres user by sending specially crafted interval or order parameters. This is critical because it gives an internal user the ability to take complete control of the database system.

Technical detail

CWE-77 (Improper Neutralization of Special Elements used in a Command) allows a Backup Operator to achieve RCE as the postgres user via malicious interval or order parameters. The attack requires valid Backup Operator credentials but results in full system compromise under the database process context.

Summary generated and translated by AI from the official description.
This vulnerability allows a Backup Operator to perform remote code execution (RCE) as the postgres user by sending a malicious interval or order parameter.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.