Type confusion regarding input of PostgreSQL ctid data type selectivity estimator allows an object creator to view a calculation derived from the value of an arbitrary 4-byte span of memory, via a chosen non-ctid input. While the calculation loses precision, substantial memory value recovery appears possible. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-14668 is a type confusion vulnerability in PostgreSQL's ctid data type selectivity estimator that allows an authenticated object creator to leak arbitrary memory values. By submitting non-ctid inputs to the estimator function, attackers can trigger calculations on unintended memory regions and recover substantial portions of sensitive data through statistical analysis of the returned values. This affects PostgreSQL versions before 18.5, 17.11, 16.15, 15.19, and 14.24—impacting organizations running unpatched database instances. The vulnerability is particularly dangerous in multi-tenant environments or where untrusted users have schema creation privileges, as it provides a direct path to information disclosure without requiring elevated permissions.
While this CVE does not map to specific MITRE ATT&CK techniques, Casky's Claude AI engine with extended reasoning can identify the attack surface by correlating type confusion patterns (CWE-843) with database query behavior anomalies. Practitioners using Casky would detect suspicious activity through patterns indicating: (1) repeated queries to system estimator functions with malformed input types, (2) unusual result set distributions from selectivity calculations that deviate from normal query planning, and (3) database object creation followed immediately by estimator function calls—a behavioral sequence inconsistent with legitimate workloads. The platform's 754 security skills would flag CWE-843 exploitation attempts by monitoring function parameter validation failures and memory access patterns, enabling teams to identify reconnaissance activity before actual data exfiltration occurs.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-14668. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation