Description
pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, undo_partition() reads part_config.time_encoder as unrestricted text and interpolates it without identifier quoting into a dynamically executed SELECT statement. A role with partman_user access can store SQL rather than a function name, and the SQL executes with the privileges of the caller that invokes undo_partition(). The function is not part of the default background-worker path, which limits the automatic superuser escalation described by the related create-partition vulnerability, but a privileged caller can still have its available confidentiality, integrity, and availability permissions abused. This issue is fixed in version 5.5.0.
Published: 2026-09-18
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: SQL injection allowing execution of arbitrary queries by roles with partman_user access
Action: Immediate Patch
AI Analysis

Impact

The pg_partman extension can treat the part_config.time_encoder field as plain text and concatenate it into a SELECT statement without proper quoting. A role that has partman_user privileges can store malicious SQL as the time_encoder value, which then executes with the privileges of whoever calls undo_partition(). This flaw permits unauthenticated SQL injection that may read, modify, or delete data within the database, leading to significant confidentiality, integrity, and availability impacts.

Affected Systems

The vulnerability exists in the pg_partman PostgreSQL extension for all versions preceding 5.5.0. Users of any PostgreSQL deployment that have installed pg_partman and granted partman_user access to roles that might invoke undo_partition() are affected. The fixed version is 5.5.0 and later.

Risk and Exploitability

The CVSS score of 8.5 indicates a high severity of the flaw. No EPSS score is currently available, but the lack of listing in CISA KEV does not diminish the risk; attackers can exploit the vulnerability by crafting a malicious time_encoder value and executing undo_partition(). The exploitation requires database-level access and the presence of the vulnerable extension, but once achieved, it grants the attacker the privileges of the executing role.

Generated by OpenCVE AI on September 19, 2026 at 11:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update pg_partman to version 5.5.0 or later, which removes the vulnerability.
  • If immediate upgrade is not feasible, limit the partman_user role to trusted users only and revoke permissions to execute undo_partition() until the patch is applied.
  • Implement strict input validation on the part_config.time_encoder field to ensure only valid function names are stored, preventing injection of arbitrary SQL.

Generated by OpenCVE AI on September 19, 2026 at 11:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Pgxn
Pgxn pg Partman
Vendors & Products Pgxn
Pgxn pg Partman

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, undo_partition() reads part_config.time_encoder as unrestricted text and interpolates it without identifier quoting into a dynamically executed SELECT statement. A role with partman_user access can store SQL rather than a function name, and the SQL executes with the privileges of the caller that invokes undo_partition(). The function is not part of the default background-worker path, which limits the automatic superuser escalation described by the related create-partition vulnerability, but a privileged caller can still have its available confidentiality, integrity, and availability permissions abused. This issue is fixed in version 5.5.0.
Title pg_partman SQL injection in undo partition time encoder
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-19T14:11:36.597Z

Reserved: 2026-07-10T20:17:57.992Z

Link: CVE-2026-61818

cve-icon Vulnrichment

Updated: 2026-09-19T14:02:35.360Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T20:17:19.780

Modified: 2026-09-24T21:22:19.873

Link: CVE-2026-61818

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:00:21Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')