{"id":"CVE-2026-50736","details":"The pglogical queue mechanism, used to convey out-of-band commands such as replicated DDL from a publisher to a subscriber, executes message payloads on the subscriber at the privilege level of the apply worker, which is equivalent to a PostgreSQL superuser in default installations. A party acting as the publisher can send crafted queue messages that cause arbitrary SQL to be executed on the subscriber as superuser, escalating from a role permitted to use pglogical to full superuser and breaking the isolation between tenants in shared deployments. To exploit the issue an attacker must be able to direct a subscription at an endpoint they control. In default installations this requires privileges normally reserved for a superuser, so the issue is most relevant to managed deployments where the ability to create subscriptions has been delegated to non-superuser roles.","modified":"2026-08-27T19:14:04.922444Z","published":"2026-07-28T19:17:36.700Z","references":[{"type":"ADVISORY","url":"https://www.enterprisedb.com/docs/security/advisories/cve202650736/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/2ndquadrant/pglogical","events":[{"introduced":"a23c44acb46cfa0e47b6f2eb54d822c475c03c89"},{"fixed":"9a0e182745885ad0152ea387988c95a483396a81"}],"database_specific":{"cpe":"cpe:2.3:a:enterprisedb:pglogical:*:*:*:*:*:postgresql:*:*","extracted_events":[{"introduced":"2.0.0"},{"fixed":"2.4.8"}],"source":"CPE_RANGE"}}],"versions":["REL2_4_7","REL2_4_6","REL2_4_5","REL2_4_4","REL2_4_3","REL2_4_2","REL2_4_1","REL2_4_0","REL2_3_4","REL2_3_3","REL2_3_2","REL2_3_1","REL2_3_0","REL2_2_2","REL2_2_1","REL2_2_0","REL2_1_1","REL2_1_0","REL2_0_1","REL2_0_0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-50736.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}