PT-2026-95648 · Pg Jobmon+1 · Pg Jobmon+1
CVE-2026-61819
·
Published
2026-09-18
·
Updated
2026-09-23
CVSS v3.1
8.5
High
| Vector | AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
pg partman versions prior to 5.5.0
Description
When pg jobmon is installed and
part config.jobmon is set to true, exception handlers in several functions place the p parent table variable verbatim into a SQL string literal used to call the pg jobmon.add job() function. A user with partman privileges can create a parent-table name containing a single quote to terminate the literal and inject SQL. If the pg partman bgw process reaches the affected exception path, the injected SQL executes with pg partman bgw.role privileges, which typically default to PostgreSQL superuser. This can lead to full database compromise and the execution of operating-system commands as the PostgreSQL service account. The persistent part config row may trigger this escalation during subsequent maintenance ticks.Recommendations
Update to version 5.5.0.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pg Jobmon
Pg Partman