PT-2026-95650 · Postgresql · Pg Partman

CVE-2026-61821

·

Published

2026-09-18

·

Updated

2026-10-03

CVSS v3.1

8.5

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions pg partman versions prior to 5.5.0
Description pg partman is a PostgreSQL extension used for managing partitioned tables by time or ID. The functions drop partition id() and drop partition time() utilize part config.retention schema as the target for the ALTER TABLE SET SCHEMA operation and accept any non-empty schema name. A user with partman user access can specify a target schema for which they lack the required CREATE privilege. Because the background worker executes the relocation using pg partman bgw.role privileges, which typically default to PostgreSQL superuser, the standard authorization checks for the ALTER TABLE SET SCHEMA operation are bypassed. This allows the unauthorized relocation of retained child tables between schemas.
Recommendations Update to version 5.5.0.

Exploit

Fix

LPE

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-61821
ECHO-E95D-6841-C84A
GHSA-PXP2-X8CF-RFHC

Affected Products

Pg Partman