PT-2026-95645 · Unknown · Pg Partman

CVE-2026-61781

·

Published

2026-09-18

·

Updated

2026-09-23

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions pg partman versions prior to 5.5.0
Description The create partition time() function reads the time encoder value from the part config table and interpolates it into a dynamically executed SELECT statement without proper identifier quoting. A user with partman user INSERT and UPDATE privileges can inject SQL instead of a function name. When the pg partman bgw worker creates a child partition for a text- or UUID-keyed set, it executes the injected SQL with pg partman bgw.role privileges, which typically default to PostgreSQL superuser. This can lead to database-wide compromise and the execution of operating-system commands as the PostgreSQL service account.
Recommendations Update pg partman to version 5.5.0.

Exploit

Fix

SQL injection

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-61781
ECHO-EEE1-BD2D-6964
GHSA-742W-3J7C-QWVP

Affected Products

Pg Partman