Description
The postgresql-operator charm runs a Prometheus postgres_exporter to collect database metrics using a dedicated "monitoring" PostgreSQL user. On database connection errors, the exporter writes the monitoring user's password in cleartext to its logs. Any actor able to read those logs can recover the password, which grants read-only pg_monitor access to PostgreSQL. This is fixed in the dev track (14/edge) in revisions 1189 (arm64) and 1190 (amd64), and in the stable track (14/stable) in revisions 1216 (arm64) and 1217 (amd64).
Published: 2026-10-02
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Credential Disclosure via cleartext logging
Action: Patch Now
AI Analysis

Impact

The Prometheus postgres_exporter bundled with Canonical’s postgresql-operator writes the dedicated monitoring user's password to its logs whenever a database connection error occurs. This violates the principle of least privilege for logging and exposes login information, enabling an adversary who can read the logs to acquire a read‑only pg_monitor account. The vulnerability is a straightforward practice of recording sensitive data in logs (CWE‑532).

Affected Systems

Canonical’s postgresql-operator charm, prior to the patch updates, on both the dev track (revisions 1189 for arm64 and 1190 for amd64) and the stable track (revisions 1216 for arm64 and 1217 for amd64). Any deployment of these earlier revisions that runs the postgres_exporter component is impacted.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity. No EPSS data is available, and the flaw is not listed in CISA’s KEV catalog. Exploitation requires an actor to obtain read access to the exporter’s log files; no external network exploitation surface is known. If log access is compromised, the attacker gains a monitored database account, which can read database metadata and potentially pivot to further database operations.

Generated by OpenCVE AI on October 2, 2026 at 22:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the postgresql-operator charm to at least dev track revision 1189 (arm64) or 1190 (amd64), or stable track revision 1216 (arm64) or 1217 (amd64).
  • Restrict filesystem permissions on the postgres_exporter log files so that only privileged system accounts can read them, preventing unauthorized log inspection.
  • Configure the exporter or the monitoring user password handling to avoid writing the password to logs, such as by using secure secret management or disabling debug logging of credentials.

Generated by OpenCVE AI on October 2, 2026 at 22:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 21:00:00 +0000

Type Values Removed Values Added
Description The postgresql-operator charm runs a Prometheus postgres_exporter to collect database metrics using a dedicated "monitoring" PostgreSQL user. On database connection errors, the exporter writes the monitoring user's password in cleartext to its logs. Any actor able to read those logs can recover the password, which grants read-only pg_monitor access to PostgreSQL. This is fixed in the dev track (14/edge) in revisions 1189 (arm64) and 1190 (amd64), and in the stable track (14/stable) in revisions 1216 (arm64) and 1217 (amd64).
Title Monitoring-user password logged in cleartext by postgres_exporter in postgresql VM charm
Weaknesses CWE-532
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: canonical

Published:

Updated: 2026-10-02T20:35:50.514Z

Reserved: 2026-10-01T18:01:17.865Z

Link: CVE-2026-104055

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T21:16:54.607

Modified: 2026-10-02T21:16:54.607

Link: CVE-2026-104055

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T22:30:19Z

Weaknesses
  • CWE-532

    Insertion of Sensitive Information into Log File