Description
pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, create_partition_time() reads the writable part_config.time_encoder text value and interpolates it without identifier quoting into a dynamically executed SELECT statement. A role with the documented partman_user INSERT and UPDATE privileges can store SQL rather than a function name. When pg_partman_bgw later creates a child partition for a text- or UUID-keyed set, the worker executes the stored SQL with pg_partman_bgw.role privileges, which default to PostgreSQL superuser. The persistent configuration row can repeatedly restore elevated access on later maintenance ticks, and successful exploitation can permit database-wide compromise and operating-system command execution as the PostgreSQL service account. This issue is fixed in version 5.5.0.
Published: 2026-09-18
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability in pg_partman’s create_partition_time() allows a role with documented partman_user INSERT and UPDATE permissions to inject arbitrary SQL into the time_encoder configuration value, which is later interpolated into a dynamically executed SELECT statement. This SQL injection leads to privilege escalation, enabling the attacker to execute any database command with the permissions of the pg_partman_bgw role, which defaults to a PostgreSQL superuser. An attacker can achieve database-wide compromise and ultimately command execution at the operating‑system level under the PostgreSQL service account. The weakness is a classic SQL Injection flaw (CWE‑89) combined with a Permission Management issue (CWE‑269).

Affected Systems

All installations of the pg_partman extension before version 5.5.0 are affected. The vulnerability exists in the pg_partman package managed by the pgpartman vendor and is fixed in release 5.5.0. Users running older releases should treat any instance of pg_partman as a potential risk until a patch is applied.

Risk and Exploitability

The CVSS score of 9.9 places this flaw in the Critical range, indicating a high potential for exploitation. Although the EPSS score is currently unavailable, the absence of a KEV listing does not diminish the inherent severity. Exploitation requires the attacker to have a role that can INSERT or UPDATE into the part_config table – a privilege that may be granted to application users who schedule partition maintenance. Once this condition is met, the attacker can inject malicious SQL that will run with superuser rights during background worker operations, making the attack path efficient and requiring no additional conditions beyond the documented privileges. The potential outcome is full control of the database and underlying host, which justifies a top‑priority response.

Generated by OpenCVE AI on September 19, 2026 at 10:44 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the official vendor patch and upgrade pg_partman to version 5.5.0 or later.
  • Limit the privileges of the partman_user role so that only trusted users can INSERT or UPDATE the part_config table, and remove these privileges for untrusted roles.
  • If a patch cannot be applied immediately, review and cleanse existing time_encoder values to ensure they reference only legitimate function names, and consider disabling or restricting the pg_partman_bgw role until remediation.

Generated by OpenCVE AI on September 19, 2026 at 10:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Pgpartman
Pgpartman pg Partman
Vendors & Products Pgpartman
Pgpartman pg Partman

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, create_partition_time() reads the writable part_config.time_encoder text value and interpolates it without identifier quoting into a dynamically executed SELECT statement. A role with the documented partman_user INSERT and UPDATE privileges can store SQL rather than a function name. When pg_partman_bgw later creates a child partition for a text- or UUID-keyed set, the worker executes the stored SQL with pg_partman_bgw.role privileges, which default to PostgreSQL superuser. The persistent configuration row can repeatedly restore elevated access on later maintenance ticks, and successful exploitation can permit database-wide compromise and operating-system command execution as the PostgreSQL service account. This issue is fixed in version 5.5.0.
Title pg_partman has privilege escalation through SQL injection in create_partition_time()
Weaknesses CWE-269
CWE-89
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Pgpartman Pg Partman
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-18T20:16:17.069Z

Reserved: 2026-07-10T20:06:05.616Z

Link: CVE-2026-61781

cve-icon Vulnrichment

Updated: 2026-09-18T20:16:12.101Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T20:17:19.003

Modified: 2026-09-23T18:12:04.247

Link: CVE-2026-61781

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T19:24:47Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')