PT-2026-95645 · Unknown · Pg Partman
CVE-2026-61781
·
Published
2026-09-18
·
Updated
2026-09-23
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
pg partman versions prior to 5.5.0
Description
The
create partition time() function reads the time encoder value from the part config table and interpolates it into a dynamically executed SELECT statement without proper identifier quoting. A user with partman user INSERT and UPDATE privileges can inject SQL instead of a function name. When the pg partman bgw worker creates a child partition for a text- or UUID-keyed set, it executes the injected SQL with pg partman bgw.role privileges, which typically default to PostgreSQL superuser. This can lead to database-wide compromise and the execution of operating-system commands as the PostgreSQL service account.Recommendations
Update pg partman to version 5.5.0.
Exploit
Fix
SQL injection
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pg Partman