Bug 2538786 (CVE-2026-61817) - CVE-2026-61817 pg_partman: privilege escalation via SQL injection in several functions via time decoder
Summary: CVE-2026-61817 pg_partman: privilege escalation via SQL injection in several ...
Keywords:
Status: NEW
Alias: CVE-2026-61817
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
urgent
urgent
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2540723
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-22 20:39 UTC by OSIDB Bzimport
Modified: 2026-09-24 19:08 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-22 20:39:10 UTC
pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, run_maintenance(), show_partitions(), show_partition_info(), undo_partition(), and partition_data_time() interpolate the writable part_config.time_dncoder text value without identifier quoting into dynamic SQL. A role with the documented partman_user privileges can store SQL rather than a decoder function name. When an affected operation later uses the poisoned value, including pg_partman_bgw maintenance for a text- or UUID-keyed set, the SQL executes with the operation's privileges, which can be the default PostgreSQL superuser background-worker role. The persistent row can restore elevated access on later ticks, and successful exploitation can permit database-wide compromise and operating-system command execution as the PostgreSQL service account. This issue is fixed in version 5.5.0.


Note You need to log in before you can comment on or make changes to this bug.