Executive brief
EnterpriseDB pglogical is a tool used for logical data replication between PostgreSQL databases. A security vulnerability in its message queue mechanism allows an attacker to execute unauthorized commands with administrative (superuser) privileges on the receiving database. This could lead to full system takeover, data theft, or the bypassing of security boundaries between different customers in shared hosting environments.
Technical details
A privilege escalation vulnerability exists in the pglogical queue mechanism, which is used to replicate DDL and out-of-band commands. The root cause is that message payloads are executed on the subscriber using the 'apply worker' context, which typically operates with PostgreSQL superuser privileges. An attacker who can control a publisher or redirect a subscription to a malicious endpoint can send crafted queue messages to execute arbitrary SQL as a superuser. While this usually requires superuser privileges to set up in default installations, it poses a critical risk in managed environments where subscription management has been delegated to non-privileged roles. The issue is fixed in pglogical version 2.4.8.
Affected products
- EnterpriseDB pglogical 2.x before 2.4.8
Timeline
- 2026-07-28: disclosed
- 2026-07-28: advisory