Impact
The vulnerability in pg_partman’s create_partition_time() allows a role with documented partman_user INSERT and UPDATE permissions to inject arbitrary SQL into the time_encoder configuration value, which is later interpolated into a dynamically executed SELECT statement. This SQL injection leads to privilege escalation, enabling the attacker to execute any database command with the permissions of the pg_partman_bgw role, which defaults to a PostgreSQL superuser. An attacker can achieve database-wide compromise and ultimately command execution at the operating‑system level under the PostgreSQL service account. The weakness is a classic SQL Injection flaw (CWE‑89) combined with a Permission Management issue (CWE‑269).
Affected Systems
All installations of the pg_partman extension before version 5.5.0 are affected. The vulnerability exists in the pg_partman package managed by the pgpartman vendor and is fixed in release 5.5.0. Users running older releases should treat any instance of pg_partman as a potential risk until a patch is applied.
Risk and Exploitability
The CVSS score of 9.9 places this flaw in the Critical range, indicating a high potential for exploitation. Although the EPSS score is currently unavailable, the absence of a KEV listing does not diminish the inherent severity. Exploitation requires the attacker to have a role that can INSERT or UPDATE into the part_config table – a privilege that may be granted to application users who schedule partition maintenance. Once this condition is met, the attacker can inject malicious SQL that will run with superuser rights during background worker operations, making the attack path efficient and requiring no additional conditions beyond the documented privileges. The potential outcome is full control of the database and underlying host, which justifies a top‑priority response.
OpenCVE Enrichment