PT-2026-95649 · Unknown · Pg Partman
CVE-2026-61820
·
Published
2026-09-18
·
Updated
2026-09-22
CVSS v3.1
8.5
High
| Vector | AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
pg partman versions prior to 5.5.0
Description
The
inherit template properties() function manually surrounds primary-key column names from pg attribute.attname with double quotes without escaping embedded double-quote characters. A user with partman user privileges who owns a template table can create a crafted column name to break out of the generated ALTER TABLE ADD PRIMARY KEY identifier. When the background worker applies the key to a child partition, the resulting SQL executes with pg partman bgw.role privileges, which typically default to PostgreSQL superuser. This can lead to database-wide compromise and operating-system command execution as the PostgreSQL service account. The crafted identifier remains in the catalog and can trigger the issue during subsequent partition creations.Recommendations
Update to version 5.5.0.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pg Partman