PT-2026-95649 · Unknown · Pg Partman

CVE-2026-61820

·

Published

2026-09-18

·

Updated

2026-09-22

CVSS v3.1

8.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions pg partman versions prior to 5.5.0
Description The inherit template properties() function manually surrounds primary-key column names from pg attribute.attname with double quotes without escaping embedded double-quote characters. A user with partman user privileges who owns a template table can create a crafted column name to break out of the generated ALTER TABLE ADD PRIMARY KEY identifier. When the background worker applies the key to a child partition, the resulting SQL executes with pg partman bgw.role privileges, which typically default to PostgreSQL superuser. This can lead to database-wide compromise and operating-system command execution as the PostgreSQL service account. The crafted identifier remains in the catalog and can trigger the issue during subsequent partition creations.
Recommendations Update to version 5.5.0.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-61820
ECHO-18AF-F647-C2F7
GHSA-XQXH-6HH3-974M

Affected Products

Pg Partman