Root cause
The extension’s selectivity estimator accepted input without checking that its type matched the routine’s expectations. This broke the contract between database objects an authorized user could create and native extension code running with database-process authority.
Demonstrated impact
The vendor confirms possible code execution as the database operating-system account. A user needed permission to install the vulnerable extension, or an existing installation plus object-creation permission. The public sources do not establish a universal unauthenticated or cross-tenant compromise.
Lessons for review
- Validate input types at extension boundaries before applying native-code assumptions.
- Review extension installation and object-creation privileges together; either permission in isolation can hide the relevant trust boundary.
- Verify the vendor’s fixed releases and keep the database process identity limited to necessary resources.
Award and evidence
One individually identified competition entry. The organizer uses $; its current rules establish US-dollar notation but concern 2026, not an archived 2025 rules snapshot. Exact award decision and cash settlement are unknown.
Matched the organizer’s named PostgreSQL award to the tracker’s exact CVE, then checked the vendor advisory and CNA prerequisites. Summary remains within the published technical evidence.
- The technical basis is the vendor advisory, not a detailed researcher walkthrough; discovery reasoning beyond that evidence is unknown.
- The December competition demonstration, February advisory publication, award announcement and unknown payment date are distinct events.
- Current rules provide explicit USD context but are not the archived 2025 rules.
Recorded timeline
- Published
- 2026-02-12explicit · Publication of the vendor CNA record; no separate detailed researcher article was established.
- Public Disclosure
- 2025-12-10explicit · Public competition demonstration; separate from later vendor advisory and technical publication.
- Fixed
- 2026-02-12explicit · Vendor release date for PostgreSQL 18.2, 17.8, 16.12, 15.16 and 14.21; individual deployment dates remain unknown.
- Award Announced
- 2025-12-16explicit · Organizer recap confirms the per-entry award; decision and payment dates remain unknown.
Sources and provenance
- ZeroDay.cloud 2025 individual competition results Nir Ohfeld / Wiz Research · reviewed 2026-10-02
- ZeroDay.cloud vulnerability tracker Wiz / ZeroDay.cloud · reviewed 2026-10-02
- ZeroDay.cloud current rules: US-dollar denomination Wiz · reviewed 2026-10-02
- PostgreSQL CVE-2026-2004 security advisory PostgreSQL · reviewed 2026-10-02
- CVE-2026-2004 PostgreSQL CNA record PostgreSQL CNA / CVE Program · reviewed 2026-10-02
Record reviewed 2026-10-02. Snapshot 53796974ace8. Open the complete JSON contract.