PT-2026-95650 · Postgresql · Pg Partman
CVE-2026-61821
·
Published
2026-09-18
·
Updated
2026-10-03
CVSS v3.1
8.5
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
pg partman versions prior to 5.5.0
Description
pg partman is a PostgreSQL extension used for managing partitioned tables by time or ID. The functions
drop partition id() and drop partition time() utilize part config.retention schema as the target for the ALTER TABLE SET SCHEMA operation and accept any non-empty schema name. A user with partman user access can specify a target schema for which they lack the required CREATE privilege. Because the background worker executes the relocation using pg partman bgw.role privileges, which typically default to PostgreSQL superuser, the standard authorization checks for the ALTER TABLE SET SCHEMA operation are bypassed. This allows the unauthorized relocation of retained child tables between schemas.Recommendations
Update to version 5.5.0.
Exploit
Fix
LPE
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pg Partman