{"id":"CVE-2026-50737","details":"When applying replicated changes for a row that is missing one or more columns, pglogical evaluates the affected table's default expressions on the subscriber. Because the apply worker runs at a privilege level equivalent to a PostgreSQL superuser in default installations, any function invoked by such a default expression also runs at that privilege. A party acting as the publisher can use this path to cause functions to be executed on the subscriber as superuser, escalating from a role permitted to use pglogical to full superuser.\n\nThis is a second, independent path to the same superuser escalation tracked under CVE-2026-50736 (the pglogical queue issue). To exploit the issue an attacker must be able to direct a subscription at an endpoint they control. In default installations this requires privileges normally reserved for a superuser, so the issue is most relevant to managed deployments where the ability to create subscriptions has been delegated to non-superuser roles.","modified":"2026-08-27T19:14:05.240008Z","published":"2026-07-28T19:17:36.827Z","references":[{"type":"ADVISORY","url":"https://www.enterprisedb.com/docs/security/advisories/cve202650737/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/2ndquadrant/pglogical","events":[{"introduced":"a23c44acb46cfa0e47b6f2eb54d822c475c03c89"},{"fixed":"9a0e182745885ad0152ea387988c95a483396a81"}],"database_specific":{"extracted_events":[{"introduced":"2.0.0"},{"fixed":"2.4.8"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:enterprisedb:pglogical:*:*:*:*:*:postgresql:*:*"}}],"versions":["REL2_4_7","REL2_4_6","REL2_4_5","REL2_4_4","REL2_4_3","REL2_4_2","REL2_4_1","REL2_4_0","REL2_3_4","REL2_3_3","REL2_3_2","REL2_3_1","REL2_3_0","REL2_2_2","REL2_2_1","REL2_2_0","REL2_1_1","REL2_1_0","REL2_0_1","REL2_0_0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-50737.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}