PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107314 pgjdbc CVE debrief

The pgjdbc PostgreSQL JDBC Driver, versions 42.7.11 through 42.7.13, does not enforce the requireAuth connection property when it excludes all known authentication methods, allowing an attacker to request cleartext password authentication and potentially obtain the database password. This issue is fixed in version 42.7.14, which refuses such connections with SQLState 08004.

Vendor
pgjdbc
Product
Unknown
CVSS
MEDIUM 5.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Defenders and developers using the pgjdbc PostgreSQL JDBC Driver, especially those with applications relying on database connections and authentication, should assess their exposure and prioritize upgrading to version 42.7.14 or later.

Why it matters

The CVE-2026-107314 vulnerability in pgjdbc allows an attacker to bypass authentication, potentially leading to database password exposure. Defenders must prioritize verification and upgrades to prevent exploitation.

  • An attacker may intercept and obtain database passwords if they can position themselves between the application and its server.
  • Defenders must verify and upgrade to pgjdbc version 42.7.14 or later to prevent potential authentication bypass.
  • Applications using affected pgjdbc versions require immediate attention to prevent exposure.

Technical summary

The pgjdbc PostgreSQL JDBC Driver, versions 42.7.11 through 42.7.13, does not enforce the requireAuth connection property when it excludes all known authentication methods. This allows an attacker positioned between the application and its server to request cleartext password authentication and potentially receive the database password. The issue is fixed in version 42.7.14, which refuses such connections with SQLState 08004 and rejects values without a method as invalid.

Defensive priority

Defenders should prioritize verifying and upgrading to pgjdbc version 42.7.14 or later, especially for applications using affected versions, to prevent potential interception of database passwords.

Recommended defensive actions

  • Verify the pgjdbc version used in your application and upgrade to version 42.7.14 or later if necessary.
  • Review and adjust the requireAuth connection property to ensure it properly enforces authentication methods.
  • Monitor for any suspicious activity related to database connections and authentication requests.
  • Perform an inventory of systems and applications using the affected pgjdbc versions.
  • Review and implement compensating controls for exposed systems while remediation is scheduled.
  • Track and document exceptions during the remediation process.
  • Schedule regular rechecks of remediated assets to ensure continued protection.

Evidence notes

The CVE record and source item provide details on the affected pgjdbc versions and the fix in version 42.7.14. The requireAuth property's behavior and the potential for an attacker to request cleartext password authentication are documented.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107314 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107314

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107314 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107314

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.