PT-2026-79767 · Postgresql Global Development Group+2 · Postgresql+2

CVE-2026-78155

·

Published

2026-08-23

·

Updated

2026-08-24

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions StackGres versions prior to 1.18.9
Description A privilege escalation issue exists in the StackGres operator, which is used to deploy and manage PostgreSQL clusters on Kubernetes. A low-privilege tenant who owns a database can bypass isolation boundaries to gain administrator privileges. This occurs because the metrics exporter connects to PostgreSQL with superuser privileges and executes queries in tenant-controlled databases without sufficiently constraining the PostgreSQL search path. An attacker can influence object resolution, allowing a database object under their control to execute with elevated privileges, potentially leading to OS command execution inside the PostgreSQL pod, read/write access to co-located databases, and lateral movement within the cluster.
Recommendations Update StackGres to version 1.18.9 or later.

Fix

LPE

Untrusted Search Path

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-78155

Affected Products

Kubernetes
Postgresql
Stackgres